Bug#453838: acidbase: CVE-2007-6156 cross site scripting vulnerability

2007-12-02 Thread David Gil
It's not necesary. My usual sponsor will do it. Anyway, thanks Nico. On 02/12/2007, Nico Golde <[EMAIL PROTECTED]> wrote: > Do you want me to sponsor this upload? If yes no problem, > just ping me.

Bug#453838: acidbase: CVE-2007-6156 cross site scripting vulnerability

2007-12-02 Thread Nico Golde
Hi David, * David Gil <[EMAIL PROTECTED]> [2007-12-02 20:38]: > I've just upload the new upstream version of BASE (1.3.9) including your > fix to mentors. http://mentors.debian.net/debian/pool/main/a/acidbase/ Do you want me to sponsor this upload? If yes no problem, just ping me. Kind regards Ni

Bug#453838: acidbase: CVE-2007-6156 cross site scripting vulnerability

2007-12-02 Thread David Gil
tags 453838 +pending thanks Hello Nico, I've just upload the new upstream version of BASE (1.3.9) including your fix to mentors. http://mentors.debian.net/debian/pool/main/a/acidbase/ Thanks, David. El dom, 02-12-2007 a las 15:08 +0100, Nico Golde escribió: > Hi, > attached is a patch for an NM

Bug#453838: acidbase: CVE-2007-6156 cross site scripting vulnerability

2007-12-02 Thread Nico Golde
Hi, attached is a patch for an NMU which fixes this bug. The patch referenced in my first mail seems to be wrong, there were {} missing around the header and die. This patch is also available from: http://people.debian.org/~nion/nmu-diff/acidbase-1.3.8-1_1.3.8-1.1.patch Kind regards Nico -- Nic

Bug#453838: acidbase: CVE-2007-6156 cross site scripting vulnerability

2007-12-01 Thread Nico Golde
Package: acidbase Severity: important Tags: security patch Hi, the following CVE (Common Vulnerabilities & Exposures) id was published for acidbase. CVE-2007-6156[0]: | Multiple cross-site scripting (XSS) vulnerabilities in | base_qry_main.php in Base Analysis and Security Engine (BASE) before |