CVE-2011-1589: path traversal security vulnerability

Bug #769054 reported by Ansgar Burchardt
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
libmojolicious-perl (Debian)
Fix Released
Unknown
libmojolicious-perl (Ubuntu)
Fix Released
Medium
Unassigned
Natty
Won't Fix
Medium
Unassigned

Bug Description

Binary package hint: libmojolicious-perl

Viacheslav Tykhanovskyi discovered a directory traversal vulnerability in Mojolicious, a Perl Web Application Framework.

This was fixed in Debian in 1.16-1 (unstable), 0.999926-1+squeeze1 (squeeze).

CVE References

visibility: private → public
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

Changed in libmojolicious-perl (Ubuntu Natty):
importance: Undecided → Medium
milestone: none → natty-updates
status: New → Triaged
milestone: natty-updates → none
status: Triaged → Confirmed
Changed in libmojolicious-perl (Debian):
status: Unknown → Fix Released
Revision history for this message
Angel Abad (angelabad) wrote :

This bug is fixed in Oneiric version.

Changed in libmojolicious-perl (Ubuntu):
status: Confirmed → Fix Released
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. natty has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against natty is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Changed in libmojolicious-perl (Ubuntu Natty):
status: Confirmed → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.