oss-sec mailing list archives

CVE Request: BackupPC 3.2.1 fixes cross site scripting


From: "Thijs Kinkhorst" <thijs () debian org>
Date: Tue, 13 Sep 2011 16:24:17 +0200

Hi,

BackupPC 3.2.1 was released back in April and fixed an XSS problem:

http://sourceforge.net/mailarchive/forum.php?thread_name=f1f1ef74-716d-4af8-b1bf-c1ba6d9a98a1%40SC1EXHC-02.global.atheros.com&forum_name=backuppc-devel

This is upstream's patch:

http://backuppc.cvs.sourceforge.net/viewvc/backuppc/BackupPC/lib/BackupPC/CGI/Browse.pm?r1=1.23&r2=1.24

The same code is present at least since BackupPC 3.1.0, which is the
oldest version we support. It seems no CVE id has been issued to date. Can
a CVE id please be assigned?


thanks,
Thijs


Current thread: