Your message dated Sun, 17 Jun 2007 14:22:25 +0200
with message-id <[EMAIL PROTECTED]>
and subject line Invalid bug, Moodle is not affected
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: moodle
Severity: grave
Tags: security

A security bug has been discovered in PHPMailer:

| PHPMailer 1.7, when configured to use sendmail, allows remote
| attackers to execute arbitrary shell commands via shell metacharacters
| in the SendmailSend function in class.phpmailer.php

<http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3215>
<https://sourceforge.net/tracker/index.php?func=detail&aid=1734811&group_id=26031&atid=385707>

Your package contains a copy of PHPMailer.

Please mention the name CVE-2007-3215 in the changelog when fixing
this bug.  A security update for stable may be necessary.

PS: Please remove your copy of PHPMailer and use the package
libphp-phpmailer instead.


--- End Message ---
--- Begin Message ---
Moodle is not affected by this bug. Moodle's usage of the PHPMailer functions 
is safe wrt to this bug. No upload needed to fix this.

Moodle does some modifications to PHPMailer in order to integreate it so it's 
not possible to use the standard libphpmailer package.

Best regards
-- 
Isaac Clerencia at Warp Networks, http://www.warp.es
Blog: http://people.warp.es/~isaac/blog/
Work: <[EMAIL PROTECTED]>   | Debian: <[EMAIL PROTECTED]>

Attachment: signature.asc
Description: This is a digitally signed message part.


--- End Message ---

Reply via email to