Bug#399170: Sage extension feed script insertion vulnerability

2006-11-18 Thread Stefan Fritsch
If the version in Debian is not affected by this bug, you can of course close or downgrade this bug. Note that I have never used sage and don't know how it works, but from your description it sounds like disabling HTML mode would take care of many potential vulnerabilities. So I don't see any

Bug#399170: Sage extension feed script insertion vulnerability

2006-11-18 Thread Alan Woodland
I don't have anything available to test this on right now, but I strongly suspect that this will not affect the version of Sage currently in Debian. The version currently in Debian is 1.3.7, plus my somewhat draconian patch to fix the previously reported vulnerabilities. See the bug report