the option "turn_cmd" can stall a computer or maybe start another application

Bug #173881 reported by ubuntu_demon
254
Affects Status Importance Assigned to Milestone
wesnoth (Ubuntu)
Fix Released
Undecided
Stephan Rügamer
Dapper
Fix Released
Undecided
Stephan Rügamer
Edgy
Fix Released
Undecided
Stephan Rügamer
Feisty
Fix Released
Undecided
Stephan Rügamer
Gutsy
Fix Released
Undecided
Stephan Rügamer

Bug Description

Binary package hint: wesnoth

The preference option "turn_cmd" can stall a computer or maybe start another application. Therefor this preference option is removed from wesnoth 1.2.8
1.2.6-1ubuntu2.2 doesn't have this fix according to the changelog.

see :
http://www.wesnoth.org/forum/viewtopic.php?p=264289
http://svn.gna.org/viewcvs/wesnoth/tags/1.2.8/changelog?rev=21944

CVE References

Revision history for this message
Stephan Rügamer (sruegamer) wrote :
Changed in wesnoth:
assignee: nobody → shermann
status: New → In Progress
Revision history for this message
Stephan Rügamer (sruegamer) wrote :

Forget the last link...it's the old one...

Revision history for this message
Stephan Rügamer (sruegamer) wrote :
Revision history for this message
ubuntu_demon (ubuntu-demon) wrote :

This bug is not a duplicate of bug #158414
This bug is not a duplicate of bug #172783

Wesnoth 1.2.8 fixes two security issues. One is addressed by bug #172783. I reported this bug about the other security issue

Revision history for this message
Emilio Pozuelo Monfort (pochu) wrote :

Hardy already has 1.2.8

Changed in wesnoth:
status: In Progress → Fix Released
Revision history for this message
Stephan Rügamer (sruegamer) wrote :
Emmet Hikory (persia)
Changed in wesnoth:
assignee: nobody → shermann
Revision history for this message
Stephan Rügamer (sruegamer) wrote :

Edgy version is still vulnerable to those CVEs...

CVE-2007-3917
CVE-2007-5742
CVE-2007-6201

Changed in wesnoth:
assignee: nobody → shermann
status: New → In Progress
status: New → In Progress
Changed in wesnoth:
status: New → In Progress
status: New → In Progress
assignee: nobody → shermann
Changed in wesnoth:
assignee: nobody → shermann
Revision history for this message
Stephan Rügamer (sruegamer) wrote :

Dapper version is still vulnerable to those CVEs:

CVE-2007-3917
CVE-2007-5742
CVE-2007-6201

Changed in wesnoth:
status: In Progress → Fix Released
status: In Progress → Fix Released
status: In Progress → Fix Released
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.