[Secure-testing-team] Serendipity event_entryproperties vulnerability

Thijs Kinkhorst thijs at debian.org
Wed Aug 8 12:08:51 UTC 2007


Hi,

Erich Schubert reports on his blog about a security vulnerability in the 
event_entryproperties plugin of serendipity:
http://blog.drinsama.de/erich/en/security/2007080801-security-issue-in-serendipity.html

I'm glad to report that:
- I've uploaded a fixed version to unstable with urgency=high;
- The vulnerability is not present in etch (new code in 1.1+);
- Serendipity is not present in sarge.

So this is just to report that the issue is dealt with :-)


Thijs
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 481 bytes
Desc: not available
Url : http://lists.alioth.debian.org/pipermail/secure-testing-team/attachments/20070808/4133952b/attachment.pgp 


More information about the Secure-testing-team mailing list