Your message dated Sun, 17 Jun 2007 15:10:48 +0300
with message-id <[EMAIL PROTECTED]>
and subject line Bug#429206: [CVE-2007-3163, CVE-2006-6978 etc.] FCKEditor 
issues
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: jspwiki
Severity: grave
Tags: security

Your package seems to contain a copy of FCKEditor, which has been
affected by several security issues:

<http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=FCKEditor>

Please make sure that these vulnerabilities have been fixed in your
copy, both in stable and unstable.  Thanks!

(It would be great if you could contribute to a shared FCKEditor
package, so there's just one place which needs patching.)


--- End Message ---
--- Begin Message ---
Florian Weimer <[EMAIL PROTECTED]> writes:
> Your package seems to contain a copy of FCKEditor, which has been
> affected by several security issues:

JSPWiki doesn't contain the FCKEditor, it only has support for using
it (see /usr/share/jspwiki/scripts/fckeditor/fckeditor.js contents).
It is the responsibility of the user to download the actual editor
code separately, and thus maintain it.

Closing this bug.

-- 
* Sufficiently advanced magic is indistinguishable from technology (T.P)  *
*           PGP public key available @ http://www.iki.fi/killer           *

--- End Message ---

Reply via email to