Your message dated Sun, 04 Apr 2010 08:49:56 +0000
with message-id <[email protected]>
and subject line Bug#575995: fixed in moin 1.9.2-3
has caused the Debian Bug report #575995,
regarding XSS in Despam action (CVE-2010-0828)
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
575995: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=575995
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: moin
Version: 1.5.3-1.2etch2
Severity: security
Hello,
There is a XSS in moinmoin "Despam" action (see [1] and
CVE-2010-0828[2]). Note that Despam action is only accessible to
superusers, not by regular users.
Franklin
[1] http://moinmo.in/SecurityFixes
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0828
--- End Message ---
--- Begin Message ---
Source: moin
Source-Version: 1.9.2-3
We believe that the bug you reported is fixed in the latest version of
moin, which is due to be installed in the Debian FTP archive:
moin_1.9.2-3.debian.tar.gz
to main/m/moin/moin_1.9.2-3.debian.tar.gz
moin_1.9.2-3.dsc
to main/m/moin/moin_1.9.2-3.dsc
python-moinmoin_1.9.2-3_all.deb
to main/m/moin/python-moinmoin_1.9.2-3_all.deb
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jonas Smedegaard <[email protected]> (supplier of updated moin package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: RIPEMD160
Format: 1.8
Date: Sat, 03 Apr 2010 16:27:00 +0200
Source: moin
Binary: python-moinmoin
Architecture: source all
Version: 1.9.2-3
Distribution: unstable
Urgency: high
Maintainer: Jonas Smedegaard <[email protected]>
Changed-By: Jonas Smedegaard <[email protected]>
Description:
python-moinmoin - Python clone of WikiWiki - library
Closes: 557956 575995
Changes:
moin (1.9.2-3) unstable; urgency=high
.
[ Frank Lin PIAT ]
* Add patch to fix CVE-2010-0828: XSS in Despam page.
Closes: 575995, thanks to Jamie Strandboge (Ubuntu).
.
[ Jakub Wilk ]
* Fix htdocs symlink, when compiled with python2.6.
Closes: bug#557956.
.
[ Jonas Smedegaard ]
* Drop local package-relations.mk snippet, now in main cdbs package.
* Unfuzz and refresh patches (with quilt compacting options
--no-timestamps --no-index -pab).
* Add DEP3 header to patch "CVE-2010-0828.patch".
* Stop suppressing optional build-dependencies: we need recent cdbs
anyway (to not complicate packaging with a local CDBS snippet) so
cannot please backporters anyway.
* Build-depend on devscripts and dh-buildinfo, and tighten build-
dependency on cdbs, due to above changes.
Checksums-Sha1:
4c2afb8ca29d01ebb44bfb6bfc49407e7e06ba69 1234 moin_1.9.2-3.dsc
342d6f2e7a9e123041e2435fb974f6909fe32454 113610 moin_1.9.2-3.debian.tar.gz
d6c917e01d92beee2f6a7f3b447459083a4bc982 14601884
python-moinmoin_1.9.2-3_all.deb
Checksums-Sha256:
cdf63da62c4c166de7d08a1b109e13d171d0263f6a3aeab957d781b4fd560f8b 1234
moin_1.9.2-3.dsc
d4fc3d50b0ec4827c81fa867cdb569e71b44218302e0ef16bdaf29e0482cb438 113610
moin_1.9.2-3.debian.tar.gz
b5c7ec10b9c50b28d8a82b578357e6831391b3a0a4c57558c637207cb44b2303 14601884
python-moinmoin_1.9.2-3_all.deb
Files:
2fb43cc07c83c91f8b4c981a5c2923a1 1234 net optional moin_1.9.2-3.dsc
9bc0784c6ff031b2d8b10f7043a9e3d9 113610 net optional moin_1.9.2-3.debian.tar.gz
4bce1eedfa6414b34a51e2e40dc41776 14601884 python optional
python-moinmoin_1.9.2-3_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEAREDAAYFAku3UioACgkQn7DbMsAkQLhkeQCgifatsJCSfiKQaQBGbw5yRDWn
i3AAn1qJlQfU48MVqAm/Tz0P0PzU6GTr
=rhm7
-----END PGP SIGNATURE-----
--- End Message ---