Bug#555240: qwik: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-18 Thread Jan Hauke Rahm
Dear maintainer,

I just spotted this issue during a check on RC bugs and it seems to me
you've basically abandoned this package. There are lintian issues (even
a warning) and this security issue (which is known for your package for
quite a while now).

Since there are only a few users according to popcon and no upload of
yours since 2006, I'm considering a QA removal request. Please speak up
if you want to keep maintaining this package. Otherwise I'll proceed in
10 days with the removal request.

Thanks for your cooperation!
Hauke


signature.asc
Description: Digital signature


Bug#555240: qwik: CVE-2007-2383 and CVE-2008-7720 prototypejs vulnerabilities

2009-11-08 Thread Michael Gilbert
package: qwik
version: 0.8.4.4 
severity: serious
tags: security

Hi,

Your package contains an embedded version of prototype.js that is
vulnerable to either CVE-2007-2383 (affecting prototype.js before 1.5.1)
[0], CVE-2008-7220 (affecting prototype.js before 1.6.0.2) [1], or both.

Your package embeds the following prototype.js versions:

  sid: 1.4.0_rc3
  lenny: 1.4.0_rc3
  etch: 1.4.0_rc3

This is a mass-filing, and the only checking done so far is a version
comparison, so please determine whether or not your package is itself
affected or not.  If it is not affected please close the bug with a
message indicating this along with what you did to check.

The version of your package specified above is the earliest version
with the affected embedded code.  If this version is in one or both of
the stable releases and you are affected, please coordinate with the
release team to prepare a proposed-update for your package to
stable/oldstable.

There are patches available for CVE-2007-2383 [2] and a backport for
prototypejs 1.5 for CVE-2008-7720 [3].

If you correct the problem in unstable, please make sure to include the
CVE number in your changelog.

Thank you for your attention to this problem.

Mike

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2383
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-7220
[2] http://dev.rubyonrails.org/ticket/7910
[3] 
http://prototypejs.org/2008/1/25/prototype-1-6-0-2-bug-fixes-performance-improvements-and-security



-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org