Foswiki Security: Alert CVE-2013-1666 - Remote Code Execution Vulnerability in MAKETEXT macro.

2013-02-19 Thread George Clark
y the above patch to Foswiki.pm, in the vicinity of line 4193 ---++ Action Plan with Timeline * 2013-02-12 - User discloses issue to foswiki security mailing list (John Lightsey) * 2013-02-13 - Developer verifies issue (George Clark) * 2013-02-13 - Security team triage the issue (George Clark, C

Foswiki Security Alert CVE-2012-6329, CVE-2012-6330 Remote code execution and other vulnerabilities in MAKETEXT macro

2012-12-17 Thread George Clark
iggered review of Foswiki code. * 2012-12-05 - Patched version (1.23) of Locale::Maketext is released. * 2012-12-08 - The [_99] DoS issue identified and sent to foswiki security list. * 2012-12-09 - The "remote execution" vulnerability in Locale::Maketext was confi