Bug#1069574: age-old and insecure webkit package

2024-04-21 Thread Dmitry Shachnev
Hi again Hadmut, On Sun, Apr 21, 2024 at 08:25:23PM +0300, Hadmut Danisch wrote: > Hi Dmitry, > > > even their own website > > https://wkhtmltopdf.org/status.html > > says: > >*Do not use wkhtmltopdf with any untrusted HTML* – be sure to >sanitize any user-supplied HTML/JS, otherwise it

Bug#1069574: age-old and insecure webkit package

2024-04-21 Thread Hadmut Danisch
Hi Dmitry, even their own website https://wkhtmltopdf.org/status.html says: *Do not use wkhtmltopdf with any untrusted HTML* – be sure to sanitize any user-supplied HTML/JS, otherwise it can lead to complete takeover of the server it is running on! Please consider using a

Bug#1069574: age-old and insecure webkit package

2024-04-21 Thread Dmitry Shachnev
Hi Hadmut! On Sat, Apr 20, 2024 at 09:23:37PM +0300, Hadmut Danisch wrote: > Package: libqt5webkit5 > > Version: 5.212.0~alpha4-30 > > > Hi, > > this was originally a bug report against Ubuntu 24.04 as 2061191, but since > the package is community maintained and not by Ubuntu, they asked me to >

Bug#1069574: age-old and insecure webkit package

2024-04-20 Thread Hadmut Danisch
Package: libqt5webkit5 Version: 5.212.0~alpha4-30 Hi, this was originally a bug report against Ubuntu 24.04 as 2061191, but since the package is community maintained and not by Ubuntu, they asked me to report it "upstreams". Ubuntu 24.04 beta / Debian bookworm still use libqt5webkit5.