Bug#927775: monit: CVE-2019-11454 CVE-2019-11455

2019-06-17 Thread Sergey B Kirpichev
On Wed, 12 Jun 2019 17:07:11 +0200 Ivo De Decker wrote: > As the security team considers this an issue that needs to be fixed for > buster, I'm increasing the severity. Please do not downgrade it again. Thanks for "help", security team. > Note that the revert Paul mentioned in #930313 I don't u

Processed: Re: Bug#927775: monit: CVE-2019-11454 CVE-2019-11455

2019-06-12 Thread Debian Bug Tracking System
Processing control commands: > severity -1 serious Bug #927775 {Done: Sergey B Kirpichev } [src:monit] monit: CVE-2019-11454 CVE-2019-11455 Severity set to 'serious' from 'important' -- 927775: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=927775 Debian Bug Tracking System Contact ow...@bug

Bug#927775: monit: CVE-2019-11454 CVE-2019-11455

2019-06-09 Thread Sergey B Kirpichev
severity 927775 important thanks No reasons, so revert back severity. On Tue, 4 Jun 2019 08:00:43 +0300 Sergey B Kirpichev wrote: > On Tue, 23 Apr 2019 06:53:03 +0200 Salvatore Bonaccorso > wrote: > > CVE-2019-11454[0]: > > | Persistent cross-site scripting (XSS) in http/cervlet.c in Tildesla

Bug#927775: monit: CVE-2019-11454 CVE-2019-11455

2019-06-03 Thread Sergey B Kirpichev
On Tue, 23 Apr 2019 06:53:03 +0200 Salvatore Bonaccorso wrote: > CVE-2019-11454[0]: > | Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash > | Monit before 5.25.3 allows a remote unauthenticated attacker to > | introduce arbitrary JavaScript via manipulation of an unsanitized u