Bugzilla – Bug 49881
VUL-0: CVE-2004-0097: pwlib: multiple vulnerabilities
Last modified: 2021-09-29 14:59:50 UTC
Hi Klaus. Debian published an advisory about several security related bugs in pwlib. Can you prepare a security update please. (SLEC, SL8.0 - STABLE) Patchinfo files will follow in a few minutes.
<!-- SBZ_reproduce --> http://www.debian.org/security/2004/dsa-448
Created attachment 16124 [details] pwlib_1.2.5-5woody1.diff
Hi Chris, this affects your baby. What do you think about testing?
Created attachment 16125 [details] patchinfo-box.pwlib
Created attachment 16126 [details] patchinfo.pwlib
Wow, great diff ... :-} --- pwlib-1.2.5.orig/src/ptclib/asner.cxx.orig +++ pwlib-1.2.5/src/ptclib/asner.cxx.orig @@ -0,0 +1,4453 @@ Frankly, I don't have time currently for this. If someone sees this as extremely important, please say so. IIRC, pwlib is not a default package
It is important.
Yes there are A LOT of rejects... *sigh* I will handle this within this week. Klaus you will owe me a beer for this. ;)
build packages for: - 8.0 - 8.1 - 8.2 - 9.0 - SLEC *I avoid fixing STABLE, because in this case an update can be used for fixing.* I'll submit packages tomorrow....
STABLE already has pwlib 1.6.3pre1
and this new version includes all the patches?
packages submitted....
Klaus, if stable includes all the patches, reassign this bug to me please.
submitted new packages
back to Thomas
the code is stable either is rewritten or has the fixes in place
packages approved (YOU only test).
CVE-2004-0097
CVE-2004-0097: CVSS v2 Base Score: 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)