Re: Fixed - mantis: CVE-2010-3763 xss vulnerability (Permission to upload)

2010-11-22 Thread sils
as soon as possible. > Please go ahead. About 1.1.6+dfsg-2lenny4, it was uploaded to spu. > Regards, Thanks for your time, and sorry (again) Regards, Sils signature.asc Description: OpenPGP digital signature

Fixed - mantis: CVE-2010-3763 xss vulnerability (Permission to upload)

2010-10-30 Thread sils
f you need any further info. Best regards, Sils [1] http://security-tracker.debian.org/tracker/CVE-2010-3303 [2] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=601618 diff -u mantis-1.1.6+dfsg/debian/changelog mantis-1.1.6+dfsg/debian/changelog --- mantis-1.1.6+dfsg/debian/changelog +++ mantis-

Re: Fixed - mantis: CVE-2010-3303 xss vulnerability (Permission to upload)

2010-10-24 Thread sils
"no DSA". I asked the security team, they agree to process with the fix. On 10/24/2010 08:35 PM, Florian Weimer wrote: > Please proceed with fixing this through stable-proposed-updates. > Thanks. Permission to upload? Regards, Sils -- To UNSUBSCRIBE, email to deb

Re: Fixed - mantis: CVE-2010-3303 xss vulnerability (Permission to upload)

2010-10-24 Thread sils
On 10/24/2010 07:36 PM, Adam D. Barratt wrote: On Sun, 2010-10-24 at 18:53 +0200, sils wrote: Attached you will find the diff between mantis_1.1.6+dfsg-2lenny2 (currently in s-p-u) and mantis_1.1.6+dfsg-2lenny3 with the fix for CVE-2010-3303. I did not uploaded any package until receive a

Fixed - mantis: CVE-2010-3303 xss vulnerability (Permission to upload)

2010-10-24 Thread sils
know if any other steps should be taken on my side. Don't hesitate to contact me if you need any further info. Best regards, Sils diff -u mantis-1.1.6+dfsg/debian/changelog mantis-1.1.6+dfsg/debian/changelog --- mantis-1.1.6+dfsg/debian/changelog +++ mantis-1.1.6+dfsg/debian/changelog @@

Re: mantis: CVE-2010-2574 xss vulnerability - Accepted uploaded packages

2010-09-06 Thread sils
of the package before > 1.1.8+dfsg-6 reaches its 10 days in unstable and transitions, you don't > need to do anything else; thanks for working on the update. No more updates. Thanks all of you, you're doing a great job. Regards, Sils signature.asc Description: OpenPGP digital signature

mantis: CVE-2010-2574 xss vulnerability - Accepted uploaded packages

2010-09-05 Thread sils
other steps should be taken on my side, maybe send another email asking for freeze exception? or whatever is necessary to do. Thanks for your time, Best regards, Sils [0] http://release.debian.org/proposed-updates/stable.html signature.asc Description: OpenPGP digital signature