Bug#911842: prayer: Information disclosure via Referrer: header

2018-10-25 Thread Salvatore Bonaccorso
Control: retitle -1 prayer: CVE-2018-18655: Information disclosure via Referrer: header Hi, This issue got CVE-2018-18655 assigned from MITRE. Regards, Salvatore

Bug#911842: prayer: Information disclosure via Referrer: header

2018-10-25 Thread Matthew Vernon
Package: prayer Version: 1.3.5-dfsg1-4+b1 Severity: important Tags: security upstream patch Hi, prayer includes a Referrer header when users click on a link in their email; this header includes the user's username, e.g.: https://aragorn.weathertop.principate.org.uk/session/matthew:17095//AAAE@di