Bug#940823: dokuwiki: Various CVE not fixed in stretch

2019-09-21 Thread Klaus Fuerstberger
Hi Salvatore, yes you are right, then I must have installed it in jessie and have been running it for years with serious bugs. Since there is still LTS support for jessie, these security-critical bugs should be fixed. @Maintainer So it's not a good idea if a package is suddenly not updated

Bug#940823: dokuwiki: Various CVE not fixed in stretch

2019-09-20 Thread Salvatore Bonaccorso
Hi, On Fri, Sep 20, 2019 at 01:51:41PM +0200, Klaus Fuerstberger wrote: > Package: dokuwiki > Version: 0.0.20140505.a+dfsg-4 > Severity: important > > Dear Maintainer, > > today I scanned my Debian oldstable installation with the OpenVAS > framework and noticed that the dokuwiki package does

Bug#940823: dokuwiki: Various CVE not fixed in stretch

2019-09-20 Thread Klaus Fuerstberger
Package: dokuwiki Version: 0.0.20140505.a+dfsg-4 Severity: important Dear Maintainer, today I scanned my Debian oldstable installation with the OpenVAS framework and noticed that the dokuwiki package does not include important fixes. The CVE are: CVE-2017-18123 DokuWiki Reflected File Download