Summary: | <net-analyzer/smokeping-2.6.9 - "displaymode" Cross-Site Scripting Vulnerability (CVE-2012-0790) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | kfm, netmon, pva, rebecca.menessec |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://secunia.com/advisories/47678/ | ||
See Also: | http://bugs.debian.org/659899 | ||
Whiteboard: | B4 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
2012-01-20 20:50:52 UTC
*** Bug 385549 has been marked as a duplicate of this bug. *** (In reply to comment #0) > Solution: > Update to version 2.6.7. 2.6.8 has been in the tree for a long time so we could request stabilisation. (In reply to Michael Palimaka (kensington) from comment #2) > 2.6.8 has been in the tree for a long time so we could request stabilisation. It seems that 2.6.8 requires some additional dependencies: net-analyzer/smokeping/smokeping-2.6.8-r1.ebuild: DEPEND: amd64(default/linux/amd64/13.0) ['>=net-analyzer/echoping-6.0.2', 'dev-perl/RadiusPerl', 'dev-perl/Net-OpenSSH'] net-analyzer/smokeping/smokeping-2.6.8-r1.ebuild: DEPEND: x86(default/linux/x86/13.0) ['dev-perl/RadiusPerl', 'dev-perl/Net-OpenSSH'] 2013/03/04 - released version 2.6.9 * be more careful about preventing xss attacks, re http://bugs.debian.org/659899 (tobi) Arch teams, please test and mark stable: =net-analyzer/smokeping-2.6.9 =dev-perl/RadiusPerl-0.220.0 =dev-perl/Data-HexDump-0.02 =dev-perl/Net-OpenSSH-0.600.0 =dev-perl/Net-SFTP-Foreign-1.730.0 =net-analyzer/echoping-6.0.2-r2 Stable KEYWORDS : amd64 x86 amd64 stable x86 stable Vote: NO. XS only. GLSA vote: no Closing as noglsa |