Bug#481504: CVE-2008-2276: Cross-site request forgery (CSRF) vulnerability

2008-05-20 Thread Steffen Joeris
Somehow the mail was just sent to the maintainer, here is a copy for the bugreport. Hi Patrick > I haven't looked deeper in your patch, but it seems reasonable. > I have forwarded it to the developers, because they are currently > or has been working on this issue recently and I wanted to hear t

Bug#481504: CVE-2008-2276: Cross-site request forgery (CSRF) vulnerability

2008-05-19 Thread Patrick Schoenfeld
Tags 481504 confirmed thanks Hi Steffen, thanks for reporting this. I was wondering because you've written that 1.1.1 is vulnerable, which isn't in Debian, but it indeed affects 1.0.8 as well. I'm working on a package for 1.1.1 but as I'm waiting for upstream (they planned to make a bugfix releas

Processed: Re: Bug#481504: CVE-2008-2276: Cross-site request forgery (CSRF) vulnerability

2008-05-19 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]: > Tags 481504 confirmed Bug#481504: CVE-2008-2276: Cross-site request forgery (CSRF) vulnerability Tags were: patch security Tags added: confirmed > thanks Stopping processing here. Please contact me if you need assistance. Debian bug tracking