FS#50344 - [websvn] Backport patch for CVE-2016-1236
Attached to Project:
Community Packages
Opened by Remi Gacogne (rgacogne) - Wednesday, 10 August 2016, 19:52 GMT
Last edited by Sergej Pupykin (sergej) - Thursday, 11 August 2016, 10:11 GMT
Opened by Remi Gacogne (rgacogne) - Wednesday, 10 August 2016, 19:52 GMT
Last edited by Sergej Pupykin (sergej) - Thursday, 11 August 2016, 10:11 GMT
|
Details
Hi,
A XSS, CVE-2016-1236 [1], has been found in websvn <= 2.3.3. While there is still no release addressing this issue, most distributions including Debian and Red Hat have applied the patch available at [2], and I think I would be nice if we could follow their lead. Thank you! [1]: http://www.openwall.com/lists/oss-security/2016/05/05/22 [2]: https://sources.debian.net/data/main/w/websvn/2.3.3-1.2+deb8u2/debian/patches/31_CVE-2016-1236.patch |
This task depends upon