Bug#555240: qwik: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-18 Thread Jan Hauke Rahm
Dear maintainer, I just spotted this issue during a check on RC bugs and it seems to me you've basically abandoned this package. There are lintian issues (even a warning) and this security issue (which is known for your package for quite a while now). Since there are only a few users according

Bug#555240: qwik: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: qwik version: 0.8.4.4 severity: serious tags: security Hi, Your package contains an embedded version of prototype.js that is vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1) [0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both. Your package