Your message dated Tue, 25 Aug 2009 09:43:59 +0200
with message-id <[email protected]>
and subject line Fixed - just not closed.
has caused the Debian Bug report #454529,
regarding CVE-2007-5615: CRLF injection vulnerability
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
454529: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=454529
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: jetty
Severity: normal
Tags: security
Hi
The following CVE[0] has been issued against jetty:
CVE-2007-5615:
CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows
remote attackers to inject arbitrary HTTP headers and conduct HTTP
response splitting attacks via unspecified vectors.
Please mention the CVE id in the changelog, when you fix this bug.
Thanks for your efforts.
Cheers
Steffen
[0]: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5615
--- End Message ---
--- Begin Message ---
Hi
This was fixed in 6.1.19-1, but never closed. The CVE was not in the
changelog, however I have filed a new bug asking the jetty uploaders to
fix this (#543462).
~Niels
signature.asc
Description: OpenPGP digital signature
--- End Message ---