Bug#683378: CVE-2012-0283

2012-08-20 Thread Moritz Muehlenhoff
On Sat, Aug 18, 2012 at 11:38:51AM +0200, Tanguy Ortolo wrote: > Tanguy Ortolo, 2012-08-17 11:04+0200: >> I have just had a look to the code: squeeze is affected. I shall >> prepare an update by hand. > > Well, after looking more closely, it appears that in fact, it is not. > The fix for versio

Bug#683378: CVE-2012-0283

2012-08-18 Thread Tanguy Ortolo
Tanguy Ortolo, 2012-08-17 11:04+0200: I have just had a look to the code: squeeze is affected. I shall prepare an update by hand. Well, after looking more closely, it appears that in fact, it is not. The fix for version 0.0.20120125 in testing does apply to 0.0.20091225 in stable after some m

Bug#683378: CVE-2012-0283

2012-08-17 Thread Tanguy Ortolo
Jonathan Wiltshire, 2012-08-17 09:37+0100: Thanks. If this is indeed the case please confirm so that the security tracker can be updated, it currently thinks squeeze is affected. I have just had a look to the code: squeeze is affected. I shall prepare an update by hand. -- ,--. : /` ) Ta

Bug#683378: CVE-2012-0283

2012-08-17 Thread Jonathan Wiltshire
Hi, On 2012-08-16 13:08, Tanguy Ortolo wrote: I do not think this is necessary. The fix is for a flaw in the last version of DokuWiki, and it does not apply to the previous one which is currently in squeeze. I will have to double-check that, but I think that version is not concerned. Thank

Bug#683378: CVE-2012-0283

2012-08-16 Thread Tanguy Ortolo
Hello Jonathan. Jonathan Wiltshire, 2012-08-16 11:15-: Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites

Bug#683378: CVE-2012-0283

2012-08-16 Thread Jonathan Wiltshire
Package: dokuwiki Dear maintainer, Recently you fixed one or more security problems and as a result you closed this bug. These problems were not serious enough for a Debian Security Advisory, so they are now on my radar for fixing in the following suites through point releases: squeeze (6.0.6) -

Bug#683378: CVE-2012-0283

2012-07-31 Thread Moritz Muehlenhoff
Package: dokuwiki Severity: important Tags: security Please see: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0283 http://secunia.com/secunia_research/2012-24/ http://bugs.dokuwiki.org/index.php?do=details&task_id=2561 This doesn't warrant a DSA, but you can fix it through a stable poin