Bug#526594: CVE-2009-1482: cross-site scripting (XSS) issue [moin 1.5 / oldstable not affected]

2009-05-06 Thread Steffen Joeris
On Tue, 5 May 2009 09:28:08 pm Jonas Smedegaard wrote: On Tue, May 05, 2009 at 09:54:36AM +0200, Frank Lin PIAT wrote: P.S. can you upload moin 1.7, I can't since I am not DD/DM. I'll do it now! - Jonas Also, please upload fixed packages for unstable with urgency high. :) Cheers Steffen

Bug#526594: CVE-2009-1482: cross-site scripting (XSS) issue [moin 1.5 / oldstable not affected]

2009-05-06 Thread Frank Lin PIAT
On Wed, 2009-05-06 at 21:22 +1000, Steffen Joeris wrote: On Tue, 5 May 2009 09:28:08 pm Jonas Smedegaard wrote: On Tue, May 05, 2009 at 09:54:36AM +0200, Frank Lin PIAT wrote: P.S. can you upload moin 1.7, I can't since I am not DD/DM. I'll do it now! - Jonas Also, please upload

Bug#526594: CVE-2009-1482: cross-site scripting (XSS) issue [moin 1.5 / oldstable not affected]

2009-05-05 Thread Frank Lin PIAT
On Sat, 2009-05-02 at 12:40 +1000, Steffen Joeris wrote: the following CVE (Common Vulnerabilities Exposures) id was published for moin. CVE-2009-1482[0]: | Multiple cross-site scripting (XSS) vulnerabilities in | action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote |

Bug#526594: CVE-2009-1482: cross-site scripting (XSS) issue [moin 1.5 / oldstable not affected]

2009-05-05 Thread Jonas Smedegaard
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Tue, May 05, 2009 at 09:54:36AM +0200, Frank Lin PIAT wrote: P.S. can you upload moin 1.7, I can't since I am not DD/DM. I'll do it now! - Jonas - -- * Jonas Smedegaard - idealist og Internet-arkitekt * Tlf.: +45 40843136 Website:

Bug#526594: CVE-2009-1482: cross-site scripting (XSS) issue

2009-05-02 Thread Frank Lin PIAT
Hi, On Sat, 2009-05-02 at 12:40 +1000, Steffen Joeris wrote: CVE-2009-1482[0]: | Multiple cross-site scripting (XSS) vulnerabilities in | action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote | attackers to inject arbitrary web script or HTML via (1) an AttachFile | sub-action in

Bug#526594: CVE-2009-1482: cross-site scripting (XSS) issue

2009-05-01 Thread Steffen Joeris
Package: moin Severity: important Tags: patch, security Hi, the following CVE (Common Vulnerabilities Exposures) id was published for moin. CVE-2009-1482[0]: | Multiple cross-site scripting (XSS) vulnerabilities in | action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote | attackers to