Installed fml 3.0+beta.20000106-2 (all source)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.6
Date: Sun, 28 Oct 2001 03:50:27 +0900
Source: fml
Binary: fml
Architecture: source all
Version: 3.0+beta.20000106-2
Distribution: stable
Urgency: high
Maintainer: Fumitoshi UKAI <ukai@debian.or.jp>
Description:
fml - Mailing List Server Package
Changes:
fml (3.0+beta.20000106-2) stable; urgency=HIGH
.
* FML Advisory 2001-001: $AUTO_HTML_GEN pass through invalid URL
http://www.fml.org/software/fml/advisories/FA2001_001/
- If you use HTML generation features by $AUTO_HTML_GEN,
invalid URL may be appeared in generated HTML files. This is the case
when you use $AUTO_HTML_GEN or html generation by using spool2html.pl.
HTML generation features in fml didn't escape <> chars of Subject:
in index pages.
- workaround fixes are one of the followings:
1) $AUTO_HTML_GEN = 0;
this configuration stops HTML generation in fml, so this vulnerability
would be closed.
2) update libsynchtml.pl and libhtmlsubr.pl
and run "make spool2html" to re-generate HTML pages.
3) wait version 4.0.3, which will be released in the near future.
.
This deb version includes fixed version of libsynchtml.pl and
libhtmlsubr.pl from ftp://ftp.fml.org/pub/fml/workaround-fix/
.
If you want to use fml's HTML generation features, I recommend you
upgrade fml package immediately.
Files:
57d8473c2d182044ccdfbc16c8d8fc4f 607 mail extra fml_3.0+beta.20000106-2.dsc
14a3a88273447cba7d0ac21c11b49d66 19854 mail extra fml_3.0+beta.20000106-2.diff.gz
511e26b2c5a1d695d6a5db75927d3073 2134258 mail extra fml_3.0+beta.20000106-2_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: KUHASIKU WA http://www.gnupg.org/ WO GORANKUDASAI
iD8DBQE72wie9D5yZjzIjAkRAtewAKClHLHexB4IJtmFF7JJ1lCQ9NBqLACfXUES
gu2WBQ1hbrWzSKdQDfdHH2I=
=VMVK
-----END PGP SIGNATURE-----
Installed:
fml_3.0+beta.20000106-2.dsc
to pool/main/f/fml/fml_3.0+beta.20000106-2.dsc
fml_3.0+beta.20000106-2.diff.gz
to pool/main/f/fml/fml_3.0+beta.20000106-2.diff.gz
fml_3.0+beta.20000106-2_all.deb
to pool/main/f/fml/fml_3.0+beta.20000106-2_all.deb
Reply to: