On Wed, 6 Sep. 2017, 07:03 Dominic Hargreaves <[email protected]> wrote: > I have just become aware of an old security issue that was fixed > in upstream: > > > https://github.com/michaelryanmcneill/shibboleth/commit/1d65ad6786282d23ba1865f5 > 6e2fd19188e7c26a > <https://github.com/michaelryanmcneill/shibboleth/commit/1d65ad6786282d23ba1865f56e2fd19188e7c26a> > > > Given that noone has noticed and reported this as an issue for a year > in the Debian package, and I'm not completely sure of how easy it is > to exploit, I'm not exactly sure of the correct severity or whether > this warrants a DSA or just a point release update. I'm CCing > the Wordpress maintainer in case they have any ideas. > > This bug will be fixed in unstable shortly. > Hi, Probably a security team question but the un-patched plugin permits a XSS attack so it should be a DSA I think.
- Craig > -- Craig Small https://dropbear.xyz/ csmall at : enc.com.au Debian GNU/Linux https://www.debian.org/ csmall at : debian.org Mastodon: @[email protected] Twitter: @smallsees GPG fingerprint: 5D2F B320 B825 D939 04D2 0519 3938 F96B DF50 FEA5

