Bug#650009: [Pkg-erlang-devel] Bug#650009: yaws vulnerable to directory traversal using ..\\

2011-11-26 Thread Sergei Golovan
On Sat, Nov 26, 2011 at 12:36 AM, Sergei Golovan sgolo...@nes.ru wrote: On Fri, Nov 25, 2011 at 7:04 PM, Fabian Linzberger e...@lefant.net wrote: A directory traversal vulnerability in yaws has been discovered and disclosed at [1]. At least the version of yaws currently in sid (1.91) is

Bug#650009: yaws vulnerable to directory traversal using ..\\

2011-11-25 Thread Fabian Linzberger
Package: yaws Version: 1.91-1 Severity: critical Tags: security upstream sid Hi, A directory traversal vulnerability in yaws has been discovered and disclosed at [1]. At least the version of yaws currently in sid (1.91) is affected. One can reproduce the issue by running: curl

Bug#650009: [Pkg-erlang-devel] Bug#650009: yaws vulnerable to directory traversal using ..\\

2011-11-25 Thread Sergei Golovan
On Fri, Nov 25, 2011 at 7:04 PM, Fabian Linzberger e...@lefant.net wrote: A directory traversal vulnerability in yaws has been discovered and disclosed at [1]. At least the version of yaws currently in sid (1.91) is affected. One can reproduce the issue by running: curl