Your message dated Mon, 03 Mar 2008 10:32:02 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#466935: fixed in webcalendar 1.1.6-7
has caused the Debian Bug report #466935,
regarding webcalendar: CVE-2007-6696: multiple XSS vulnerabilities
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)
--
466935: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=466935
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
--- Begin Message ---
Package: webcalendar
Severity: important
Tags: security
Hi,
The following issue has been reported against webcalendar:
Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow
remote attackers to inject arbitrary web script or HTML via (1) an event
description, (2) the query string to pref.php, and (3) the adv parameter to
search.php. NOTE: vector 1 requires user authentication.
(see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6696)
Can you please verify whether this applies to the version unstable and if so,
get it fixed? Please include the CVE id in any uploads fixing this problem.
thanks,
Thijs
pgpW4CuVGjiaE.pgp
Description: PGP signature
--- End Message ---
--- Begin Message ---
Source: webcalendar
Source-Version: 1.1.6-7
We believe that the bug you reported is fixed in the latest version of
webcalendar, which is due to be installed in the Debian FTP archive:
webcalendar_1.1.6-7.diff.gz
to pool/main/w/webcalendar/webcalendar_1.1.6-7.diff.gz
webcalendar_1.1.6-7.dsc
to pool/main/w/webcalendar/webcalendar_1.1.6-7.dsc
webcalendar_1.1.6-7_all.deb
to pool/main/w/webcalendar/webcalendar_1.1.6-7_all.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Rafael Laboissiere <[EMAIL PROTECTED]> (supplier of updated webcalendar package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Sun, 24 Feb 2008 00:47:40 +0100
Source: webcalendar
Binary: webcalendar
Architecture: source all
Version: 1.1.6-7
Distribution: experimental
Urgency: low
Maintainer: WebCalendar Debian package development <[EMAIL PROTECTED]>
Changed-By: Rafael Laboissiere <[EMAIL PROTECTED]>
Description:
webcalendar - PHP-Based multi-user calendar
Closes: 466935
Changes:
webcalendar (1.1.6-7) experimental; urgency=low
.
* debian/patches/13_CVE-2007-6696.dpatch: Fixes for the three cross-site
scripting (XSS) vulnerabilites described in CVE-2007-6696 (closes:
#466935)
* debian/sql/upgrade-*/1.1.6-7: Force the ALLOW_HTML_DESCRIPTION
configuration variable to 'N', as part of the fix for the
vulnerability above
* debian/NEWS.Debian: Add a note explaining the conservative change of
ALLOW_HTML_DESCRIPTION
Files:
d7bf41624b98f04d14e1e0a3256366e5 954 web optional webcalendar_1.1.6-7.dsc
f81fa98f8b1a0e7b840f56c77ed76ed2 42304 web optional webcalendar_1.1.6-7.diff.gz
1ac9943bf0417325db9fd8a9a5bea9e1 1358806 web optional
webcalendar_1.1.6-7_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)
iD8DBQFHy9Enk3oga0pdcv4RAplzAKCAUbxbfquFBlYysfPfGj58AGxbbgCeOA6Q
XB+4lFRIvsX8Fp2SEGVCdxo=
=hJIT
-----END PGP SIGNATURE-----
--- End Message ---