[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: XSS in pgstatus code



On Mon, Feb 13, 2012 at 11:04:05PM +0100, info@moritz-naumann.com wrote:
> For what it's worth, I first reported this in July 2007 and repeatedly
> since then, to various contacts, also including other issues. See also
> rt.debian.org ticket #151. I do know Debian is all volunteer run. Still,
> also because of the good work the security teams are doing,
> I had hoped for a better responsiveness (this is 4,5 years now) to such
> issues.

I think it's no secret that we were low on manpower back then.  It never
landed on my desk since I joined that part of the project in 2009.
Also you said in your mail that you "just" came across this issue.

RT #151 is secret, so I can't even access it.  You could've just
reported a bug about it publically.  (But then I acknowledge that
there probably wasn't an appropriate pseudo-package back then, apart
from the web one maybe.)

Kind regards
Philipp Kern

Attachment: signature.asc
Description: Digital signature


Reply to: