Bug#624516: patches against git

2011-10-03 Thread Paul Gevers
> i don't see the patches though, what branch did you put them in? As this is a security update for lenny, I put them on the debian-lenny branch. Paul signature.asc Description: OpenPGP digital signature

Bug#624516: patches against git

2011-10-02 Thread sean finney
Hi Paul, On Sun, Oct 02, 2011 at 08:50:19PM +0200, Paul Gevers wrote: > I uploaded the patches. At this moment I think the review is the main > thing. As I mentioned, I did my best and am currently using my patched > package on my web-site machine. (Should I also upload my latest working > d/chang

Bug#624516: patches against git

2011-10-02 Thread Paul Gevers
> Sorry about the additional delay on my end, then. You should be added now. > Go ahead and commit directly to the repo, if there are any questions or > you want some review we can work from that. I uploaded the patches. At this moment I think the review is the main thing. As I mentioned, I did m

Bug#624516: patches against git

2011-10-01 Thread sean finney
Hi Paul, On Thu, Sep 22, 2011 at 09:48:51PM +0200, Paul Gevers wrote: > @Sean, if you give me access to the cacti git on Alioth I can commit my > changes. I did request membership several days/weeks ago, but have not > seen any response. Sorry about the additional delay on my end, then. You shou

Bug#624516: patches against git

2011-09-22 Thread Paul Gevers
> For the list of issues, see: > http://security-tracker.debian.org/tracker/source-package/cacti > under "Open unimportant issues" (it's a bug that they're listed there, > only the first issue is actually unimportant and may be ignored for lenny) > > Are you in a position to check each of these an

Bug#624516: patches against git

2011-08-12 Thread Paul Gevers
> Thanks for your help and sorry that we didn't get around to processing > this package earlier. NP. > I have taken a look and the package looks fine. However, there are other > open Cacti issues in Lenny aswell, and I don't think it would make sense > to release an update that includes a fix for

Bug#624516: patches against git

2011-08-12 Thread Thijs Kinkhorst
Hi Paul, On Thu, August 11, 2011 22:45, Paul Gevers wrote: > On 07/03/11 19:35, Paul Gevers wrote: >> As discussed below and in bug 624516, I prepared a patch for >> CVE-2010-1644: cacti: XSS issues in host.php and data_sources.php in >> lenny. The maintainer of cacti suggested to contact you for

Bug#624516: patches against git

2011-08-11 Thread Paul Gevers
On 07/03/11 19:35, Paul Gevers wrote: > As discussed below and in bug 624516, I prepared a patch for > CVE-2010-1644: cacti: XSS issues in host.php and data_sources.php in > lenny. The maintainer of cacti suggested to contact you for further > actions. I read [1] and prepared a .diff.gz and .dsc fo

Bug#624516: patches against git

2011-07-03 Thread Paul Gevers
Hi security team, As discussed below and in bug 624516, I prepared a patch for CVE-2010-1644: cacti: XSS issues in host.php and data_sources.php in lenny. The maintainer of cacti suggested to contact you for further actions. I read [1] and prepared a .diff.gz and .dsc for you that you can find att

Bug#624516: patches against git

2011-07-02 Thread Mahyuddin Susanto
tag 624516 patch stop Hi Paul, On 07/02/2011 02:09 AM, Paul Gevers wrote: > Please find attached three patches against the pkg-cacti git branch > debian-lenny to fix this bug. > > Feel free to use them. > > Paul Thanks, it would to nice if we counsult with debian-security team. you can find th

Bug#624516: patches against git

2011-07-01 Thread Paul Gevers
Please find attached three patches against the pkg-cacti git branch debian-lenny to fix this bug. Feel free to use them. Paul From 4c6b9f2dc8af687f288218575388619c9528c346 Mon Sep 17 00:00:00 2001 From: Paul Gevers Date: Fri, 1 Jul 2011 20:30:53 +0200 Subject: [PATCH 1/3] Fix CVE-2010-1644 XSS i