[roundup] [CVE-2008-1474] cross-site scripting vulnerability
Bug #227276 reported by
disabled.user
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
roundup (Debian) |
Fix Released
|
Unknown
|
|||
roundup (Ubuntu) |
Fix Released
|
High
|
William Grant | ||
Dapper |
Won't Fix
|
Undecided
|
Unassigned | ||
Feisty |
Won't Fix
|
Undecided
|
Unassigned | ||
Gutsy |
Won't Fix
|
Undecided
|
Unassigned | ||
Hardy |
Fix Released
|
High
|
William Grant | ||
Intrepid |
Fix Released
|
High
|
William Grant |
Bug Description
Binary package hint: roundup
References:
DSA-1554-1 (http://
QuotingDSA-1554-1:
"Roundup, an issue tracking system, fails to properly escape HTML input,
allowing an attacker to inject client-side code (typically JavaScript)
into a document that may be viewed in the victim's browser."
Quoting CVE-2008-1474:
"Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unknown impact and attack vectors, some of which may be related to cross-site scripting (XSS)."
CVE References
Changed in roundup: | |
status: | Unknown → Fix Released |
Changed in roundup: | |
assignee: | nobody → wgrant |
importance: | Undecided → High |
status: | New → In Progress |
assignee: | nobody → wgrant |
importance: | Undecided → High |
status: | New → In Progress |
To post a comment you must log in.
Does this mean 8.04's roundup is susceptible as things stand? I see all those "nominated" for release after release. I was planning on installing it, but now I'm not sure.