On Sun, 2008-08-03 at 21:09 +0100, Kai Hendry wrote:
> Package: wnpp
> Severity: wishlist
> Owner: Kai Hendry <[EMAIL PROTECTED]>
> 
> * Package name    : nostromo
>   Version         : 1.8.6
>   Upstream Author : Marcus Glocker <[EMAIL PROTECTED]>
> * URL             : http://www.nazgul.ch/dev.html
> * License         : MIT
>   Programming Lang: C
>   Description     : small, simple, fast and secure httpd

"Secure"?  Even though it allows parent directory traversal?  As has
been said time and time again, Debian doesn't need yet another tiny
httpd that inevitably turns out to have such flaws.

It doesn't get URI decoding right either.

Ben.

-- 
Ben Hutchings
Nothing is ever a complete failure; it can always serve as a bad example.

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to