Bug 148865 - CAN-2004-1004 multiple issues with mc (CAN-2004-1005 & CAN-2004-1176)
Summary: CAN-2004-1004 multiple issues with mc (CAN-2004-1005 & CAN-2004-1176)
Keywords:
Status: CLOSED DUPLICATE of bug 152889
Alias: None
Product: Fedora Legacy
Classification: Retired
Component: mc
Version: fc2
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Fedora Legacy Bugs
QA Contact:
URL:
Whiteboard: LEGACY, 2
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2005-02-16 14:20 UTC by Josh Bressers
Modified: 2007-04-18 17:19 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2005-07-13 12:08:19 UTC
Embargoed:


Attachments (Terms of Use)

Description Josh Bressers 2005-02-16 14:20:06 UTC
*** This bug has been split off bug 148864 ***

------- Original comment by Josh Bressers (Security Response Team) on 2005.02.16
09:15 -------

Two issues with mc have been reported to the Debian BTS.  You can find more
information here:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=295261

Comment 1 Josh Bressers 2005-02-16 14:20:59 UTC
This issue should also affect FC2.

Comment 2 Jindrich Novy 2005-02-18 10:08:40 UTC
FC3, devel packages are unaffected.

The FC2 version needs to be patched.

Comment 3 Leonard den Ottolander 2005-02-22 23:38:13 UTC
Don't forget CAN-2004-1176.

Comment 4 Jindrich Novy 2005-03-01 08:56:15 UTC
Josh, do you have any objections to release the FC2 update with the newer
mc-4.6.1-pre3? This version is not vulnerable to all noted CANs. I did basic 
testing under FC2 and it works fine. (I did FC3 update with the same mc 
version recently and have no bugreports since that time related to security or 
other issues)

Comment 5 Jindrich Novy 2005-03-17 14:27:14 UTC
testing update of mc-4.6.1-pre3 is now signed and pushed.

Comment 6 Matthew Miller 2005-04-12 03:32:35 UTC
This doesn't ever appear to have been pushed from testing, and FC2 is now in the
hands of Fedora Legacy.

Comment 7 Matthew Miller 2005-04-12 04:12:38 UTC
*** Bug 127973 has been marked as a duplicate of this bug. ***

Comment 8 Jindrich Novy 2005-04-12 12:27:35 UTC
Yes, it's still in testing. I'll contact Bill if it's possible to move it to final.

Comment 9 Matthew Miller 2005-04-12 13:37:25 UTC
Are there any known issues with the in-testing package? Thanks!

Comment 10 Leonard den Ottolander 2005-04-12 22:35:04 UTC
No issues since pre2 I believe. These issues only affect plain 4.6.0 and before.

Like bug 127973 (which is *not* a dup of this bug) this issue can be closed
ERRATA afaict.


Comment 11 Matthew Miller 2005-04-12 22:45:05 UTC
Reopening, because, like bug #127973, the errata hasn't actually been released.

Comment 12 Leonard den Ottolander 2005-04-12 22:52:02 UTC
Hi Matt. Just collisioned as I was doing the exact same thing ;-) . See bug
127973. <g>

Comment 13 Matthew Miller 2005-04-12 22:58:01 UTC
Hmmm, must be time for me to go get some supper. :)

Comment 14 Marc Deslauriers 2005-07-12 23:32:26 UTC
Packages were pushed to updates-testing.

Comment 15 Pekka Savola 2005-07-13 05:11:28 UTC
I'd suggest this bug be closed, and tracking continued in #152889 ?

Comment 16 Marc Deslauriers 2005-07-13 12:08:19 UTC
Good idea.

*** This bug has been marked as a duplicate of 152889 ***


Note You need to log in before you can comment on or make changes to this bug.