Your message dated Fri, 24 Jul 2009 19:18:40 +0200
with message-id <[email protected]>
and subject line doesn't affect verlihub
has caused the Debian Bug report #538234,
regarding CVE-2009-2569: Multiple cross-site scripting (XSS) vulnerabilities
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
538234: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538234
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: verlihub
Severity: serious
Tags: security
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for verlihub.
CVE-2009-2569[0]:
| Multiple cross-site scripting (XSS) vulnerabilities in Verlihub
| Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary
| web script or HTML via (1) the nick parameter in a login action to
| index.php or (2) the URI in a news request to index.html.
If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2569
http://security-tracker.debian.net/tracker/CVE-2009-2569
Cheers,
Giuseppe
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAkppeDEACgkQNxpp46476aqoCQCgnO55QxWaLhrFZT7GMgFBM6Fr
5NcAnjraj4zDajmPFV3BJk4dcSBtfAAD
=jhle
-----END PGP SIGNATURE-----
--- End Message ---
--- Begin Message ---
Hi,
this bug doesn't affect verlihub in Debian but only so I am
closing this bug.
Cheers
Nico
--
Nico Golde - http://www.ngolde.de - [email protected] - GPG: 0xA0A0AAAA
For security reasons, all text in this mail is double-rot13 encrypted.
pgpLrV7OKwrME.pgp
Description: PGP signature
--- End Message ---