Re: [SECURITY] [DSA 1836-1] New fckeditor packages fix arbitrary code execution

2009-07-20 Thread Dominic Hargreaves
On Thu, Jul 16, 2009 at 07:55:39PM +0200, Moritz Muehlenhoff wrote: Vinny Guido discovered that multiple input sanitising vulnerabilities in Fckeditor, a rich text web editor component, may lead to the execution of arbitrary code. For the record, request-tracker3.8 currently embeds a

Re: Debian bug 531341

2009-07-20 Thread Nicolas François
Hello, On Mon, Jul 20, 2009 at 02:01:27PM -0500, tallg...@austin.rr.com wrote: I think that you're confusing the requirement that unknown user names not be logged, because they might be a user's password with the non-existent requirement that all unknown user names be treated like root and

Re: Debian bug 531341

2009-07-20 Thread Julie
Nicolas, I've taken the bug e-mail address out of the Cc list -- don't think this discussion would be productive there. I had a feeling you weren't going to be able to quote a source -- the interpretation of the requirement is contradicting the clear intent of another requirement. This