Your message dated Mon, 29 Mar 2010 11:36:47 +0200
with message-id <4bb074af.1050...@debian.org>
and subject line Re: Bug#575789: CVE-2009-4612: Multiple cross-site scripting
(XSS) vulnerabilities
has caused the Debian Bug report #575789,
regarding CVE-2009-4612: Multiple cross-site scripting (XSS) vulnerabilities
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
575789: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=575789
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: jetty
Severity: serious
Tags: security
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for jetty.
CVE-2009-4612[0]:
| Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP
| Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote
| attackers to inject arbitrary web script or HTML via the PATH_INFO to
| the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3)
| jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.
If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4612
http://security-tracker.debian.org/tracker/CVE-2009-4612
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEARECAAYFAkuwcRIACgkQNxpp46476aqFQACfZT/VLAtvNsFzBdrp3PfkyT+7
wO0An1n6VphW/zuRRLhhZhwstA40+k28
=ExF3
-----END PGP SIGNATURE-----
--- End Message ---
--- Begin Message ---
Version: 6.1.22-1
Sorry, this was already fixed
signature.asc
Description: OpenPGP digital signature
--- End Message ---