Bug#691062: viewvc: XSS bug in diff view

2012-10-20 Thread Nicolás Alvarez
Kurt Seifried from Redhat has assigned the identifier CVE-2012-4533 to this issue (thanks!). -- Nicolás -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#691062: viewvc: XSS bug in diff view

2012-10-20 Thread Nicolás Alvarez
found 691062 0.9.4+svn20060318-1 thanks I tested every version in snapshot.debian.org and they are all affected, if the hr_funout setting (show function names in diffs) is enabled. Although only 1.1.5+ seem to have it enabled by default. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@list