Bug#816780: roundup: CVE-2014-6276: information leak

2016-03-31 Thread Kai Storbeck
On 22/03/16 21:20, Salvatore Bonaccorso wrote: > Hi Kai, > > On Sat, Mar 05, 2016 at 08:45:53AM +0100, Salvatore Bonaccorso wrote: > [...] >> >From Kai Storbeck it looks the way forward would be to have roundup >> removed for unstable and stretch. Kai can you confirm that this is >> still the plan

Bug#816780: roundup: CVE-2014-6276: information leak

2016-03-22 Thread Salvatore Bonaccorso
Hi Kai, On Sat, Mar 05, 2016 at 08:45:53AM +0100, Salvatore Bonaccorso wrote: [...] > >From Kai Storbeck it looks the way forward would be to have roundup > removed for unstable and stretch. Kai can you confirm that this is > still the plan vs. update to new upstream releases? > > If so can you f

Bug#816780: roundup: CVE-2014-6276: information leak

2016-03-04 Thread Salvatore Bonaccorso
Source: roundup Version: 1.4.20-1 Severity: grave Tags: security upstream fixed-upstream wheezy jessie stretch sid Hi https://www.debian.org/security/2016/dsa-3502: |Ralf Schlatterbeck discovered an information leak in roundup, a |web-based issue tracking system. An authenticated attacker could u