Your message dated Sun, 14 Jan 2007 21:34:26 +0100
with message-id <[EMAIL PROTECTED]>
and subject line Closed in version 2.0.21-6
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: phpbb2
Severity: grave
Tags: security
Justification: user security hole

phpbb2 2.0.22 fixes some more security issues:

CVE-2006-6841:
Certain forms in phpBB before 2.0.22 lack session checks

CVE-2006-6840:
Unspecified vulnerability in phpBB before 2.0.22 has unknown impact
and remote attack vectors related to a "negative start parameter."

CVE-2006-6839:
Unspecified vulnerability in phpBB before 2.0.22 has unknown impact
and remote attack vectors related to "criteria for 'bad' redirection
targets."

See
http://www.phpbb.com/phpBB/viewtopic.php?f=14&t=489624

Please mention the CVE ids in the changelog.


--- End Message ---
--- Begin Message ---
Version: 2.0.21-6

Hi,

This bug was closed in the recent 2.0.21-6 upload of phpbb2, but the
changelog had the wrong bug number in it.


Thijs

Attachment: signature.asc
Description: This is a digitally signed message part


--- End Message ---

Reply via email to