Your message dated Mon, 29 Mar 2010 19:40:37 +0200
with message-id <4bb0e615.6020...@thykier.net>
and subject line Re: CVE-2009-4610: Multiple cross-site scripting (XSS)
vulnerabilities - Unaffected
has caused the Debian Bug report #575790,
regarding CVE-2009-4610: Multiple cross-site scripting (XSS) vulnerabilities
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
575790: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=575790
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: jetty
Severity: serious
Tags: security
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for jetty.
CVE-2009-4610[0]:
| Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty
| 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or
| HTML via (1) the query string to jsp/dump.jsp in the JSP Dump feature,
| or the (2) Name or (3) Value parameter to the default URI for the
| Session Dump Servlet under session/.
If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4610
http://security-tracker.debian.org/tracker/CVE-2009-4610
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEARECAAYFAkuwcgcACgkQNxpp46476aooGACfRAQ+Lv/EALknfgtlij4HEInk
TBYAnRyPlkiNxHrTyjdAmy/ln8y9frY9
=Yfen
-----END PGP SIGNATURE-----
--- End Message ---
--- Begin Message ---
Version: 6.1.22-1
Hi
jetty 6.1.22-1 in Debian is unaffected, since the exploitable servlet is
not shipped.
~Niels
signature.asc
Description: OpenPGP digital signature
--- End Message ---