CVE-2010-3205 affects textpattern package

2013-05-20 Thread Steven Chamberlain
Hi, CVE-2010-3205 in the Textpattern CMS was marked 'NOT-FOR-US', but there is a package of the affected version 4.2.0 in oldstable: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3205 The patch tracker and changelog do not suggest this was addressed, other than the (orphaned) package

Re: CVE-2010-3205 affects textpattern package

2013-05-20 Thread Steven Chamberlain
On 20/05/13 14:58, Steven Chamberlain wrote: CVE-2010-3205 in the Textpattern CMS was marked 'NOT-FOR-US', but there is a package of the affected version 4.2.0 in oldstable: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3205 By the way, I can't confirm that the vulnerability assigned