please remove twiki from lenny

2008-12-21 Thread Nico Golde
Hi, please remove the twiki package from testing. twiki is a regular candidate for security issues that pop up. Currently it has two security issues unfixed (one[0] enables an attacker to do code execution) and there was lately no progress on fixing the bug. For the other issue[1] there is also

Re: please remove twiki from lenny

2008-12-21 Thread Dominic Hargreaves
On Sun, Dec 21, 2008 at 02:14:45PM +0100, Nico Golde wrote: please remove the twiki package from testing. twiki is a regular candidate for security issues that pop up. Currently it has two security issues unfixed (one[0] enables an attacker to do code execution) and there was lately no

Re: please remove twiki from lenny

2008-12-21 Thread Nico Golde
Hi, * Dominic Hargreaves d...@earth.li [2008-12-21 18:20]: On Sun, Dec 21, 2008 at 02:14:45PM +0100, Nico Golde wrote: please remove the twiki package from testing. twiki is a regular candidate for security issues that pop up. Currently it has two security issues unfixed (one[0] enables an

Re: please remove twiki from lenny

2008-12-21 Thread Luk Claes
Nico Golde wrote: Hi, please remove the twiki package from testing. twiki is a regular candidate for security issues that pop up. Currently it has two security issues unfixed (one[0] enables an attacker to do code execution) and there was lately no progress on fixing the bug. For the other

Re: Bug#508257: Bug#508256: please remove twiki from lenny

2008-12-21 Thread Sven Dowideit
Sadly, the upstream fix doesn't address the root cause of the url parameter problem (and we've reported to them at least one exploit that is unfixed by their patch), and I'm working on the Foswiki fork of twiki, which is addressing the security issues we know about in what I consider a more