Bug#603748: [Pkg-erlang-devel] Bug#603748: Bug#603748: CVE-2010-4181

2010-11-17 Thread Moritz Muehlenhoff
On Wed, Nov 17, 2010 at 11:51:47PM +0300, Sergei Golovan wrote: > On Wed, Nov 17, 2010 at 11:34 AM, Sergei Golovan wrote: > > > > So, I'm closing this bug and will notify YAWS authors shortly. > > > > The YAWS author has fixed this bug in git repository. I don't think > that it's necessary > to a

Bug#603748: [Pkg-erlang-devel] Bug#603748: Bug#603748: CVE-2010-4181

2010-11-17 Thread Sergei Golovan
On Wed, Nov 17, 2010 at 11:34 AM, Sergei Golovan wrote: > > So, I'm closing this bug and will notify YAWS authors shortly. > The YAWS author has fixed this bug in git repository. I don't think that it's necessary to apply this patch to YAWS packages in Debian. https://github.com/klacke/yaws/comm

Bug#603748: [Pkg-erlang-devel] Bug#603748: CVE-2010-4181

2010-11-16 Thread Sergei Golovan
On Wed, Nov 17, 2010 at 1:06 AM, Moritz Muehlenhoff wrote: > > The following vulnerability has been reported in YAWS: > > | Directory traversal vulnerability in Yaws 1.89 allows remote attackers > | to read arbitrary files via ..\ (dot dot backslash) and other > | sequences. > > http://cve.mitre.o

Bug#603748: CVE-2010-4181

2010-11-16 Thread Moritz Muehlenhoff
Package: yaws Severity: grave Tags: security The following vulnerability has been reported in YAWS: | Directory traversal vulnerability in Yaws 1.89 allows remote attackers | to read arbitrary files via ..\ (dot dot backslash) and other | sequences. http://cve.mitre.org/cgi-bin/cvename.cgi?name=