Your message dated Thu, 14 Jan 2010 12:54:56 +0100
with message-id <20100114115455.ga19...@pool.math.tu-berlin.de>
and subject line Re: viewvc: CVE-2009-3618 and CVE-2009-3619 xss and character
printing
has caused the Debian Bug report #560903,
regarding viewvc: CVE-2009-3618 and CVE-2009-3619 xss and character printing
vulnerabilities
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
560903: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560903
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: viewvc
Version: 1.0.9-1
Severity: serious
Tags: security
Hi,
the following CVE (Common Vulnerabilities & Exposures) ids were
published for viewvc.
CVE-2009-3618[0]:
| Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0
| before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject
| arbitrary web script or HTML via the view parameter. NOTE: some of
| these details are obtained from third party information.
CVE-2009-3619[1]:
| Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before
| 1.1.2 has unknown impact and remote attack vectors related to
| "printing illegal parameter names and values."
I have been unable to track a patch down, but these are claimed fixed
in version 1.1.2. Please check whether this version is affected. Etch
and lenny may also be affected as well.
If you fix the vulnerabilities please also make sure to include the
CVE ids in your changelog entry.
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3618
http://security-tracker.debian.org/tracker/CVE-2009-3618
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3619
http://security-tracker.debian.org/tracker/CVE-2009-3619
--- End Message ---
--- Begin Message ---
Version: 1.0.9-1
Michael, please check your claims better, both issues have
been fixed long time ago:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=545779
Cheers
Nico
--- End Message ---