Comment 12 for bug 172783

Revision history for this message
Emilio Pozuelo Monfort (pochu) wrote :

wesnoth (1.2.6-1ubuntu2.2) gutsy-security; urgency=low

  * SECURITY UPDATE: Do not allow '../' in file paths. It allowed others
    to view the content of files in the remote computers.
  * debian/patches/CVE-2007-5742: added, taken from upstream SVN r21904.
  * References:
    CVE-2007-5742.
    LP: #172783.

 -- Emilio Pozuelo Monfort <email address hidden> Sun, 02 Dec 2007 21:30:03 +0100