[Bug 312215] Re: Please merge cmus 2.2.0-1.1 (multiverse) from Debian unstable (main).

Launchpad Bug Tracker 312215 at bugs.launchpad.net
Mon Dec 29 17:00:07 GMT 2008


This bug was fixed in the package cmus - 2.2.0-1.1ubuntu1

---------------
cmus (2.2.0-1.1ubuntu1) jaunty; urgency=low

  * Merge from debian unstable (LP: #312215), Ubuntu remaining changes:
    - ffmpeg.c: use correct headers location to fix FTBFS with recent ffmpeg
      snapshots (LP: #311007).

cmus (2.2.0-1.1) unstable; urgency=high

  * Non-maintainer upload by the Security Team.
  * Modify example script cmus-status-display to write the current
    status to .cmus-status in the user's home instead of /tmp/cmus-status,
    since the latter could lead to symlink attacks. CVE-2008-5375
    (Closes: #509277)

 -- Alessio Treglia <quadrispro at ubuntu.com>   Mon, 29 Dec 2008 17:36:47
+0100

** Changed in: cmus (Ubuntu)
       Status: Confirmed => Fix Released

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2008-5375

-- 
Please merge cmus 2.2.0-1.1 (multiverse) from Debian unstable (main).
https://bugs.launchpad.net/bugs/312215
You received this bug notification because you are a member of Ubuntu
Sponsors for universe, which is a direct subscriber.



More information about the Ubuntu-universe-sponsors mailing list