Format: 1.7 Date: Wed, 29 Apr 2009 08:32:35 -0500 Source: apport Binary: apport python-problem-report python-apport apport-retrace apport-gtk apport-qt Architecture: all i386_translations Version: 0.108.4 Distribution: hardy Urgency: low Maintainer: Ubuntu/i386 Build Daemon Changed-By: Jamie Strandboge Description: apport - automatically generate crash reports for debugging apport-gtk - GTK+ frontend for the apport crash report system apport-qt - Qt4 frontend for the apport crash report system apport-retrace - tools for reprocessing Apport crash reports python-apport - apport crash report handling library python-problem-report - Python library to handle problem reports Launchpad-Bugs-Fixed: 357024 Changes: apport (0.108.4) hardy-security; urgency=low . * etc/cron.daily/apport: Only attempt to remove files and symlinks, do not descend into subdirectories of /var/crash/. Doing so might be exploited by a race condition between find traversing a huge directory tree, changing an existing subdir into a symlink to e. g. /etc/, and finally getting that piped to rm. Patch based on work from Martin Pitt. Thanks to Stephane Chazelas for discovering this! - LP: #357024 - CVE-2009-1295 Files: 2a61c23a4fcd822dc148151e8b68c447 104590 utils optional apport_0.108.4_all.deb cddea8d0b747eb77306e026f43e8c099 7662 raw-translations - apport_0.108.4_i386_translations.tar.gz 9f8dc7432955def5e5476d7332ffb725 58658 python optional python-problem-report_0.108.4_all.deb 875f5505b1e258eee1c455cfc270c7f9 56970 python optional python-apport_0.108.4_all.deb a6b693e4cd22e222a052c0818e43eb2b 63690 devel optional apport-retrace_0.108.4_all.deb 4bc790aa6618eecfa27e5b8222e5766f 55292 gnome optional apport-gtk_0.108.4_all.deb d1ac561fe9a5c980cc4150a9939cb722 54048 kde optional apport-qt_0.108.4_all.deb