Bug#952785: buster-pu: package dojo/1.15.0+dfsg1-1+deb10u1

2020-03-03 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2020-03-02 at 11:28 +0100, Xavier wrote: > Le 01/03/2020 à 22:52, Andreas Beckmann a écrit : > > > +#CVE-2019-10785.patch > > > > The patch is commented in the series file and thus does not get > > applied. > > > > Andreas > > Sorry for this error. Here is

Bug#952785: buster-pu: package dojo/1.15.0+dfsg1-1+deb10u1

2020-03-02 Thread Xavier
Le 01/03/2020 à 22:52, Andreas Beckmann a écrit : >> +#CVE-2019-10785.patch > > The patch is commented in the series file and thus does not get applied. > > Andreas Sorry for this error. Here is the real patch. Cheers, Xavier diff --git a/debian/changelog b/debian/changelog index

Bug#952785: buster-pu: package dojo/1.15.0+dfsg1-1+deb10u1

2020-03-01 Thread Andreas Beckmann
> +#CVE-2019-10785.patch The patch is commented in the series file and thus does not get applied. Andreas

Bug#952785: buster-pu: package dojo/1.15.0+dfsg1-1+deb10u1

2020-02-29 Thread Xavier
Le 29/02/2020 à 14:48, Salvatore Bonaccorso a écrit : > Hi Xavier, > > On Sat, Feb 29, 2020 at 09:10:51AM +0100, Xavier Guimard wrote: >> Package: release.debian.org >> Severity: normal >> Tags: buster >> User: release.debian@packages.debian.org >> Usertags: pu >> >> Hi, >> >> dojo is

Bug#952785: buster-pu: package dojo/1.15.0+dfsg1-1+deb10u1

2020-02-29 Thread Salvatore Bonaccorso
Hi Xavier, On Sat, Feb 29, 2020 at 09:10:51AM +0100, Xavier Guimard wrote: > Package: release.debian.org > Severity: normal > Tags: buster > User: release.debian@packages.debian.org > Usertags: pu > > Hi, > > dojo is vulnerable to Cross-site Scripting. This is due to >

Bug#952785: buster-pu: package dojo/1.15.0+dfsg1-1+deb10u1

2020-02-29 Thread Xavier Guimard
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Hi, dojo is vulnerable to Cross-site Scripting. This is due to dojox.xmpp.util.xmlEncode only encoding the first occurrence of each character, not all of them. This upstream patch