Comment 5 for bug 1353046

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package reportbug - 6.5.0+nmu1ubuntu2

---------------
reportbug (6.5.0+nmu1ubuntu2) utopic; urgency=medium

  * Use 6.5.0 as version to match release regex that excludes +nmu.

reportbug (6.5.0+nmu1ubuntu1) utopic; urgency=medium

  * Merge from Debian unstable. Remaining changes (LP: #1353046):
    - bin/reportbug: If bts=ubuntu or unconfigured, exit with an
      an error and refer user "ubuntu-bug" instead.
    - reportbug/__init__.py: Match reportbug version with package version.
    - debian/control: Add prominent note to package description.
    - debian/rules, debian/dirs: Do not install .desktop file.

reportbug (6.5.0+nmu1) unstable; urgency=high

  * Non-maintainer upload.
  * CVE-2014-0479: Arbitrary code execution in compare_versions.
    A man-in-the-middle attacker could put shell metacharacters in the
    version number, causing execution of code of their choice.
    Thanks to Jakub Wilk <email address hidden>
 -- Scott Kitterman <email address hidden> Tue, 05 Aug 2014 15:19:08 -0400