Your message dated Wed, 16 Sep 2026 13:34:14 +0000
with message-id <[email protected]>
and subject line Bug#1145369: fixed in znc 1.10.3-1
has caused the Debian Bug report #1145369,
regarding znc: please update bundled jQuery (CVE-2020-11022, CVE-2020-11023)
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1145369: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145369
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: znc
Version: 1.10.2-1
Severity: important
Tags: security
X-Debbugs-Cc: [email protected], [email protected]

The ZNC web interface ships a bundled copy of jQuery 1.11.2 at:
  webskins/_default_/pub/jquery-1.11.2.js

This version is vulnerable to XSS via DOM manipulation methods
(CVE-2020-11022, CVE-2020-11023, fixed in jQuery 3.5.0). Since ZNC
actively serves this file to users via its web interface, the XSS
vulnerability is exploitable via the ZNC web UI.

Please update the bundled jQuery to 3.5.0 or later, or remove the
bundled copy and use the system libjs-jquery package instead.

Reference:
  https://security-tracker.debian.org/tracker/CVE-2020-11022
  https://github.com/advisories/GHSA-gxr4-xjj5-5px2

Found by: Attack of the Clones GSoC 2026 pipeline
  (salsa.debian.org/rouca/gsoc2026)

Gajendra Nath Soren

--- End Message ---
--- Begin Message ---
Source: znc
Source-Version: 1.10.3-1
Done: Patrick Matthäi <[email protected]>

We believe that the bug you reported is fixed in the latest version of
znc, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Patrick Matthäi <[email protected]> (supplier of updated znc package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Wed, 16 Sep 2026 15:04:37 +0200
Source: znc
Architecture: source
Version: 1.10.3-1
Distribution: unstable
Urgency: high
Maintainer: Patrick Matthäi <[email protected]>
Changed-By: Patrick Matthäi <[email protected]>
Closes: 1145369
Changes:
 znc (1.10.3-1) unstable; urgency=high
 .
   * New upstream release.
     - Fixes CVE-2026-82373 and CVE-2026-82374.
     - Updated jQuery. Fixes CVE-2020-11022 and CVE-2020-11023.
       Closes: #1145369
   * Update debian/copyright years.
   * Adjust lintian overrides.
Checksums-Sha1:
 2c54158b18f6bc17924b85cd2e80f7f35b2b1c61 2444 znc_1.10.3-1.dsc
 bddb815d3159e42f6f556e9888dda424129ad355 2313669 znc_1.10.3.orig.tar.gz
 f6da28058f3b0f7051d39a60a77f9d907aa06bb2 870 znc_1.10.3.orig.tar.gz.asc
 b7ddd91aecebc86c4cd75e802d7eb4c19e22f406 512372 znc_1.10.3-1.debian.tar.xz
 52dd2c0d1c4e60c1b216884786ab14b3a12a8f72 8095 znc_1.10.3-1_source.buildinfo
Checksums-Sha256:
 ccd0b2c397ac26556adee95946783f97f3488e31b91b3d2687abbe30eb60a290 2444 
znc_1.10.3-1.dsc
 68f3f6641b480c041010c5596e1234043e05c9137eda06233845017603095f5b 2313669 
znc_1.10.3.orig.tar.gz
 f52694233898782a305f19bb15c928ad57adc7148a2122fd38660bf63981d0e3 870 
znc_1.10.3.orig.tar.gz.asc
 e945eb96f710b6e209c5a3c2f6e8dad6bd32510edba26ca164aa305ffc154d8e 512372 
znc_1.10.3-1.debian.tar.xz
 84134904563380d39ad4c5466882030b6d1b07057421ca7205d11c522cbca259 8095 
znc_1.10.3-1_source.buildinfo
Files:
 9679e23891359149bcbcec0d06639493 2444 net optional znc_1.10.3-1.dsc
 3a6040a4f394d05fe133b442d274df55 2313669 net optional znc_1.10.3.orig.tar.gz
 a015726b6690fda16aa65828c83ee1c8 870 net optional znc_1.10.3.orig.tar.gz.asc
 57284e4305f90a870066c3c90f0f7981 512372 net optional znc_1.10.3-1.debian.tar.xz
 d06582358b63ad8056d01b6cf1a9902f 8095 net optional 
znc_1.10.3-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEWKA9xYJCWk3IuQ4TEtmwSpDL2OQFAmqql+IACgkQEtmwSpDL
2OR1Iw//Vfx43ETseNEEMo5DwjE76pzSIGehSVPa9k8ARL/l16x9yzqJf1PehVBr
ZcuT9lxMkZnPdbn4kuWy9OXYAM4B1ZaZNyEkNLKStz2lly80RIOj0DHqQ9uULHGQ
CPRqhGTtCPhSVSq6Zbv6HtR0iWb3uLxYWZiypMZUnojsPTaX4MXx3dcB7JSLz65b
BprWmNAu5nxSbk3GeME1hNE584gtz1tERF15YUVywWGlGcTk2hB9tczoPpx3KUFC
oXc5Cm99JXcRtP8ByL7qt9+8aIEQO0ekSkcjuGeoEIYAOZEKsoixxnnGBt/MJ+0S
ubXm4L5kR+n2rugWRCIypjBemM49ksh3/XyapXT2k0sIqvnbaIUfizPKiiHYuE0Z
FVipB0zeZ4G5FjTvbSa86BPCD2vPyOuUVHnd0uXt+1aF0hVBfSJFJfX0ESQhTDaI
D3EGJ9rDYrkiLhDlXNDhBvc0+hZIgvLksia6Y6UgbmTjwbpZ2w20J1+T6k6gjApz
lTXetNZx67DO0A/RyZjHPR9DQmS59ZlnYMMBtWuSqXxT0wddVJd8oW63KfbMf6aw
cIN7CcjAAmK6x65n0ANz/sDH0uOMJWSUr7kUByZRtIUHjzAFudMxw8L4PPPg8NBQ
RgZ/2oZ6KO15Em8HG2GgDGlIwlY8pspYEDQSj4R0xKnnS1V0ODA=
=PQGW
-----END PGP SIGNATURE-----

Attachment: pgpa3PahV7CrB.pgp
Description: PGP signature


--- End Message ---

Reply via email to