Bug#584809: moin: Xss due to unescaped theme.add_msg to be fixed

2010-07-29 Thread Frank Lin PIAT
Hi Nicolas, Could you upload that security update for Debian stable. I have updated (and attached) that patch, to mention the CVE number as suggested by Raphael. Thanks, Franklin Nc Golde wrote: > Hi, > any news on this bug report? It's a bit sad to see a fix but nothing > happening. Frank, if

Bug#584809: moin: Xss due to unescaped theme.add_msg to be fixed

2010-07-25 Thread Nc Golde
Hi, any news on this bug report? It's a bit sad to see a fix but nothing happening. Frank, if you need sponsoring I can sponsor your upload or Jonas please pick this up and upload. I don't want to hijack this, hence the mail but it would be nice to get this fixed. Cheers Nico -- Nico Golde -

Bug#584809: moin: Xss due to unescaped theme.add_msg to be fixed

2010-07-04 Thread Jonas Smedegaard
On Sun, Jul 04, 2010 at 09:23:15PM +0200, Jonas Smedegaard wrote: On Sun, Jul 04, 2010 at 05:28:59PM +0200, Frank Lin PIAT wrote: P.S. I am working on the new upstream release for unstable, which fix this CVE. Same here. I already prepared that update last week - just forgot to push it. D

Bug#584809: moin: Xss due to unescaped theme.add_msg to be fixed

2010-07-04 Thread Jonas Smedegaard
On Sun, Jul 04, 2010 at 05:28:59PM +0200, Frank Lin PIAT wrote: Raphael Geissert wrote: This issue has been assigned CVE-2010-2487, please mention it in the uploads fixing the issues. Jonas, Franklin, does any of you have time to prepare the package for lenny? Hi Raphael, A patch is incl

Bug#584809: moin: Xss due to unescaped theme.add_msg to be fixed

2010-07-04 Thread Frank Lin PIAT
Raphael Geissert wrote: > > This issue has been assigned CVE-2010-2487, please mention it in the > uploads > fixing the issues. > > Jonas, Franklin, does any of you have time to prepare the package for > lenny? Hi Raphael, A patch is included in this BR, it just needs to be uploaded (well, one ne

Processed: Re: Bug#584809: moin: Xss due to unescaped theme.add_msg to be fixed

2010-07-02 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 584809 CVE-2010-2487: multiple XSS vulnerabilities in moin Bug #584809 [moin] moin: Xss due to unescaped theme.add_msg to be fixed Changed Bug title to 'CVE-2010-2487: multiple XSS vulnerabilities in moin' from 'moin: Xss due to unescaped