Bug#382207: CVE-2006-3990: File inclusion vulnerability in Savant2 which is included in egroupware

2006-08-13 Thread Moritz Muehlenhoff
Peter Eisentraut wrote: > Stefan Fritsch wrote: > > Please check whether the version included in egroupware is affected > > by this vulnerabilities. > > One would think that the submitter actually checked whether the bug > exists before submitting a bug? One would also think that the maintainer

Bug#382207: CVE-2006-3990: File inclusion vulnerability in Savant2 which is included in egroupware

2006-08-09 Thread Peter Eisentraut
Stefan Fritsch wrote: > Please check whether the version included in egroupware is affected > by this vulnerabilities. One would think that the submitter actually checked whether the bug exists before submitting a bug? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscrib

Bug#382207: CVE-2006-3990: File inclusion vulnerability in Savant2 which is included in egroupware

2006-08-09 Thread Stefan Fritsch
On Wednesday 09 August 2006 22:38, Peter Eisentraut wrote: > Stefan Fritsch wrote: > > Please check whether the version included in egroupware is > > affected by this vulnerabilities. > > One would think that the submitter actually checked whether the bug > exists before submitting a bug? There ar

Bug#382207: CVE-2006-3990: File inclusion vulnerability in Savant2 which is included in egroupware

2006-08-09 Thread Stefan Fritsch
Package: egroupware-core Severity: grave Tags: security Justification: user security hole Some vulnerabilities have been found in Savant2: "Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree component for Mambo and Joomla!, allow remo