Bug#363972: viewcvs: does not escape URIs correctly in parameters for diff

2006-04-20 Thread David Ayers
David Martínez Moreno schrieb: > >>So I suppose this package is not being maintained any longer (last >>'unstable' ChangeLog Thu, 21 Jul 2005) and I haven't found any 'viewvc' >>package. > > > No, you are wrong. I am maintaining it, but the switch to viewvc is not > yet > done. I am spe

Bug#363972: viewcvs: does not escape URIs correctly in parameters for diff

2006-04-20 Thread David Martínez Moreno
El jueves, 20 de abril de 2006 22:09, David Ayers escribió: > Package: viewcvs > Severity: normal [...] > So the question is, does this bug have security implications that would > allow it to be fixed in sarge? It seems that even the unstable versions of > the viewcvs package are still using an ol

Bug#363972: viewcvs: does not escape URIs correctly in parameters for diff

2006-04-20 Thread David Ayers
Package: viewcvs Severity: normal Note that the system this is being reported from is not the system on which the issue has been noted, infact viewcvs is not installed. Reference: http://gna.org/support/?func=detailitem&item_id=1058 The link generated for 'diff' is partially missing the URI esc