Bug#503330: Multiple Vulnerabilities (xss, insecure file handling and code execution)

2008-10-26 Thread Pierre Chifflier
On Fri, Oct 24, 2008 at 10:27:09PM +0200, Florian Weimer wrote: * Luca Bruno: A full disclosure bulletin has been posted today, reporting various security vulnerabilities in websvn. Thanks, I'm not sure if the source is in our public monitoring. The remote code execution should only

Bug#503330: Multiple Vulnerabilities (xss, insecure file handling and code execution)

2008-10-26 Thread Florian Weimer
* Pierre Chifflier: That looks serious indeed, and it affects versions from both testing and unstable. There are 3 different kind of problems: - Cross Site Scripting (unsafe usage of the PHP_SELF server variable within the getParameterisedSelfUrl() function) - File handling issues in the

Bug#503330: Multiple Vulnerabilities (xss, insecure file handling and code execution)

2008-10-24 Thread Luca Bruno
Package: websvn Version: 1.61-20 Severity: critical Tags: security A full disclosure bulletin has been posted today, reporting various security vulnerabilities in websvn. The remote code execution should only affect etch version, while at a first glance the others are also still open in

Bug#503330: Multiple Vulnerabilities (xss, insecure file handling and code execution)

2008-10-24 Thread Florian Weimer
* Luca Bruno: A full disclosure bulletin has been posted today, reporting various security vulnerabilities in websvn. Thanks, I'm not sure if the source is in our public monitoring. The remote code execution should only affect etch version, while at a first glance the others are also