Re: CVE-2010-3205 affects textpattern package

2013-05-21 Thread Steven Chamberlain
On 21/05/13 22:09, Moritz Muehlenhoff wrote: Thanks, I've updated the security tracker! Okay, thank you! I couldn't say for sure the exploit given the CVE is real, and there's very little interest in the package any more (orphaned, low popcon, removed); but I thought it is better to mark it as

Re: CVE-2010-3205 affects textpattern package

2013-05-21 Thread Moritz Mühlenhoff
On Tue, May 21, 2013 at 10:16:25PM +0100, Steven Chamberlain wrote: On 21/05/13 22:09, Moritz Muehlenhoff wrote: Thanks, I've updated the security tracker! Okay, thank you! I couldn't say for sure the exploit given the CVE is real, and there's very little interest in the package any more

Re: CVE-2010-3205 affects textpattern package

2013-05-21 Thread Moritz Muehlenhoff
On Mon, May 20, 2013 at 02:58:40PM +0100, Steven Chamberlain wrote: Hi, CVE-2010-3205 in the Textpattern CMS was marked 'NOT-FOR-US', but there is a package of the affected version 4.2.0 in oldstable: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3205 The patch tracker and

CVE-2010-3205 affects textpattern package

2013-05-20 Thread Steven Chamberlain
Hi, CVE-2010-3205 in the Textpattern CMS was marked 'NOT-FOR-US', but there is a package of the affected version 4.2.0 in oldstable: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3205 The patch tracker and changelog do not suggest this was addressed, other than the (orphaned) package

Re: CVE-2010-3205 affects textpattern package

2013-05-20 Thread Steven Chamberlain
On 20/05/13 14:58, Steven Chamberlain wrote: CVE-2010-3205 in the Textpattern CMS was marked 'NOT-FOR-US', but there is a package of the affected version 4.2.0 in oldstable: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3205 By the way, I can't confirm that the vulnerability assigned