Bug#611661: Bundled plugins using Xinha allow malicious file uploads

2012-05-13 Thread J.M.Roth
On 13-May-12 21:25, Moritz Mühlenhoff wrote: > On Sun, May 13, 2012 at 06:04:03PM +0100, Steve McIntyre wrote: >> On Tue, Mar 08, 2011 at 10:37:13PM +0100, Moritz Muehlenhoff wrote: >> Looking at other bugs and security tracker issues in serendipity, I'd >> be tempted to remove it from Debian anywa

Bug#611661: Bundled plugins using Xinha allow malicious file uploads

2012-05-13 Thread Moritz Mühlenhoff
On Sun, May 13, 2012 at 06:04:03PM +0100, Steve McIntyre wrote: > On Tue, Mar 08, 2011 at 10:37:13PM +0100, Moritz Muehlenhoff wrote: > >On Tue, Mar 08, 2011 at 02:02:31PM +0100, Hector Romojaro wrote: > >> Hi, > >> > >> About openacs and dotlrn packages, I don't think they are affected by > >> an

Bug#611661: Bundled plugins using Xinha allow malicious file uploads

2012-05-13 Thread Steve McIntyre
On Tue, Mar 08, 2011 at 10:37:13PM +0100, Moritz Muehlenhoff wrote: >On Tue, Mar 08, 2011 at 02:02:31PM +0100, Hector Romojaro wrote: >> Hi, >> >> About openacs and dotlrn packages, I don't think they are affected by >> any of the Xinha vulnerabilities [1][2][3]. The summary says: >> >> "Xinha sh

Bug#611661: Bundled plugins using Xinha allow malicious file uploads

2011-03-08 Thread Moritz Muehlenhoff
On Tue, Mar 08, 2011 at 02:02:31PM +0100, Hector Romojaro wrote: > Hi, > > About openacs and dotlrn packages, I don't think they are affected by > any of the Xinha vulnerabilities [1][2][3]. The summary says: > > "Xinha ships with several plugins that utilize PHP scripting for special > usage, li

Bug#611661: Bundled plugins using Xinha allow malicious file uploads

2011-03-08 Thread Hector Romojaro
Hi, About openacs and dotlrn packages, I don't think they are affected by any of the Xinha vulnerabilities [1][2][3]. The summary says: "Xinha ships with several plugins that utilize PHP scripting for special usage, like the ImageManager or ExtendedFileManager. A 0-day security exploit has been r

Bug#611661: Bundled plugins using Xinha allow malicious file uploads

2011-01-31 Thread Daniel E. Markle
Package: serendipity Version: 1.5.3-2 Summary of the problem from upstream: "Xinha ships with several plugins that utilize PHP scripting for special usage, like the ImageManager or ExtendedFileManager. A 0-day security exploit has been reported available as of today that exploits the functional