Your message dated Wed, 17 Sep 2008 13:22:58 +0100
with message-id <[EMAIL PROTECTED]>
and subject line Re: Bug#499252: CVE-2008-4079: Cross-site scripting (XSS)
vulnerability
has caused the Debian Bug report #499252,
regarding CVE-2008-4079: Cross-site scripting (XSS) vulnerability
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)
--
499252: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=499252
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
--- Begin Message ---
Package: movabletype-opensource
Severity: important
Tags: security
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for movabletype-opensource.
CVE-2008-4079[0]:
| Cross-site scripting (XSS) vulnerability in Movable Type (MT) 4.x
| through 4.20, and 3.36 and earlier; Movable Type Enterprise 4.x
| through 4.20, and 1.54 and earlier; and Movable Type Community
| Solution allows remote attackers to inject arbitrary web script or
| HTML via unspecified vectors.
If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.
Cheers
Steffen
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4079
http://security-tracker.debian.net/tracker/CVE-2008-4079
--- End Message ---
--- Begin Message ---
Version: 4.2~rc5-1
On Wed, Sep 17, 2008 at 09:44:35PM +1000, Steffen Joeris wrote:
> Hi,
> the following CVE (Common Vulnerabilities & Exposures) id was
> published for movabletype-opensource.
>
> CVE-2008-4079[0]:
> | Cross-site scripting (XSS) vulnerability in Movable Type (MT) 4.x
> | through 4.20, and 3.36 and earlier; Movable Type Enterprise 4.x
> | through 4.20, and 1.54 and earlier; and Movable Type Community
> | Solution allows remote attackers to inject arbitrary web script or
> | HTML via unspecified vectors.
>
> If you fix the vulnerability please also make sure to include the
> CVE id in your changelog entry.
This was fixed in 4.2~rc5-1 - I wasn't aware of the CVE number at the
time, however.
Thanks,
Dominic.
--
Dominic Hargreaves | http://www.larted.org.uk/~dom/
PGP key 5178E2A5 from the.earth.li (keyserver,web,email)
--- End Message ---