Your message dated Sat, 27 Jun 2009 18:20:02 +0200
with message-id <[email protected]>
and subject line Re: Bug#480887: Info received ((no subject))
has caused the Debian Bug report #480887,
regarding stable version outdated and ancient, several security issues
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
480887: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=480887
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
package: dokuwiki
version: 0.0.20061106-6
severity: important
tags +security
Hi,
thanks for packaging dokuwiki!
I just installed the version from stable and when I browse the wiki the
following lines are displayed in the top of the pages:
New release available: 2008-05-05. upgrade now! [14]
New release candidate available: 2008-04-11. upgrade now! [12]
New release candidate available: 2008-03-31. upgrade now! [11]
An XSS vulnerability was discovered, read the bug report for manual fixing or
upgrading [10]
New release available: 2007-06-26. upgrade now! [9]
New release candidate available: 2007-05-24. upgrade now! [8]
At least the XSS issue seems worthwhile fixing to me, but from a usability
point of view I would also welcome if the other liners would not be displayed
(as long as the version in stable has no security issues).
regards,
Holger
pgpR0bZ8C2AXl.pgp
Description: PGP signature
--- End Message ---
--- Begin Message ---
On Sat, Mar 21, 2009, Mohammed Adnène Trojette wrote:
> Security issues have been solved, normally. If not, please submit a bug
> tagged security. Other warnings are mostly cosmetic and as such may need
> a cosmetic upload (through volatile, probably). I have to confess that I
> did not take care of it.
As there are no security bugs reported against the stable version, I am
only updating the backport. Hence closing the report.
--
Mohammed Adnène Trojette
--- End Message ---