On Wed, 6 Sep. 2017, 07:03 Dominic Hargreaves <[email protected]> wrote:

> I have just become aware of an old security issue that was fixed
> in upstream:
>
>
> https://github.com/michaelryanmcneill/shibboleth/commit/1d65ad6786282d23ba1865f5
> 6e2fd19188e7c26a
> <https://github.com/michaelryanmcneill/shibboleth/commit/1d65ad6786282d23ba1865f56e2fd19188e7c26a>
>
>
> Given that noone has noticed and reported this as an issue for a year
> in the Debian package, and I'm not completely sure of how easy it is
> to exploit, I'm not exactly sure of the correct severity or whether
> this warrants a DSA or just a point release update. I'm CCing
> the Wordpress maintainer in case they have any ideas.
>
> This bug will be fixed in unstable shortly.
>
Hi,
  Probably a security team question but the un-patched plugin permits a XSS
attack so it should be a DSA I think.


 - Craig

> --
Craig Small             https://dropbear.xyz/     csmall at : enc.com.au
Debian GNU/Linux        https://www.debian.org/   csmall at : debian.org
Mastodon: @[email protected]             Twitter: @smallsees
GPG fingerprint:      5D2F B320 B825 D939 04D2  0519 3938 F96B DF50 FEA5

Reply via email to