On jeu., 2012-08-02 at 23:43 +0200, Frank Habermann wrote:
> Hi,
> 
> upstream has released a fixed version.
> The spellchecker versions in perl and cfm contains also this
> vulnerability.

Arf, thanks for the notice.
> 
> I will create fixed packages tomorrow.

Please try to isolate fixes from the other upstream changes (if any),
since we are in freeze. For Squeeze, please build in a clean chroot and
with -sa.
> 
> >> I will try to contact upstream to find a solution.
> > 
> > And can you check if ckeditor is affected too?
> I also asked upstream. ckeditor is not affected as i told.
> All server side stuff was removed in ckeditor.
> 
Thanks again :)

-- 
Yves-Alexis

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to