Your message dated Mon, 02 Jul 2012 04:06:06 +1000
with message-id <[email protected]>
and subject line Version: 2.6.22-2
has caused the Debian Bug report #409703,
regarding SQL-ledger unsafe for use with untrusted users or public installations
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
409703: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=409703
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: sql-ledger
Version: 2.6.22-1
Severity: important
Tags: security

Hi.
Maybe sql-ledger is affected by CVE-2007-0667.

Description:
Separate from CVE-2006-5872, there is a possibility of causing arbitrary
code execution during redirects. This requires a valid login to exploit
and was discovered and brought to the attention of both the SQL-Ledger
and LedgerSMB team in November. LedgerSMB 1.1.5 corred the problem, but
it is still not corrected in SQL-Ledger.

Reference:
http://www.frsirt.com/english/advisories/2007/0407
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0667

Note:
Please mention the CVE id in the changelog.


Thanks in advanced.


regards,
--
   .''`.
  : :' :    Alex de Oliveira Silva | enerv
  `. `'     www.enerv.net
    `-


--- End Message ---
--- Begin Message ---
Package: sql-ledger
Version: 2.6.22-2


-- 
Nikolai Lusan <[email protected]>

Attachment: signature.asc
Description: This is a digitally signed message part


--- End Message ---

Reply via email to