Re: Bug#853189: tracker.debian.org: Ecnoding issue / Code injection through Maintainer field (and probably others)

2017-02-01 Thread Niels Thykier
Christophe Siraut: > Niels Thykier wrote: >> * tracker.d.o does *not* import excuses.yaml but update_excuses.html >>(as far as I am informed at least) > > True. > > Here is a patch for tracker to parse YAML instead of HTML. > > Cheers, > Christophe > Hi Christophe, Thanks for looking

Re: Bug#853189: tracker.debian.org: Ecnoding issue / Code injection through Maintainer field (and probably others)

2017-02-01 Thread Christophe Siraut
Niels Thykier wrote: > * tracker.d.o does *not* import excuses.yaml but update_excuses.html >(as far as I am informed at least) True. Here is a patch for tracker to parse YAML instead of HTML. Cheers, Christophe >From 04692b5c65124b930a94f668cd2b409269d186c5 Mon Sep 17 00:00:00 2001 From:

Re: Bug#853189: tracker.debian.org: Ecnoding issue / Code injection through Maintainer field (and probably others)

2017-01-30 Thread Adrian Bunk
On Mon, Jan 30, 2017 at 04:48:55PM +0100, Mattia Rizzolo wrote: > On Mon, Jan 30, 2017 at 03:43:44PM +0100, Dominik George wrote: > > tracker.debian.org apparently has encoding issues, not of the “schei� > > encoding” kind, but it even seems to break the HTML completely and even > > introduces new

Re: Bug#853189: tracker.debian.org: Ecnoding issue / Code injection through Maintainer field (and probably others)

2017-01-30 Thread Niels Thykier
Mattia Rizzolo: > On Mon, Jan 30, 2017 at 03:43:44PM +0100, Dominik George wrote: >> tracker.debian.org apparently has encoding issues, not of the “schei� >> encoding” kind, but it even seems to break the HTML completely and even >> introduces new elements into the DOM in some way… >> >> أحمد

Re: Bug#853189: tracker.debian.org: Ecnoding issue / Code injection through Maintainer field (and probably others)

2017-01-30 Thread Mattia Rizzolo
On Mon, Jan 30, 2017 at 03:43:44PM +0100, Dominik George wrote: > tracker.debian.org apparently has encoding issues, not of the “schei� > encoding” kind, but it even seems to break the HTML completely and even > introduces new elements into the DOM in some way… > > أحمد المحمودي (Ahmed