[Pkg-roundcube-maintainers] Bug#508628: etch-backports still vulnerable

Holger Levsen holger at layer-acht.org
Thu Jan 15 13:04:02 UTC 2009


Hi,

On Dienstag, 13. Januar 2009, Kingsley Masters wrote:
> I'd like to comfirm this bug still exists on etch-backports and is being
> actively exploited.  Our Debian server running roundcube was comprimised
> yesterday though this bug.

Kingsley, out of curiosity, do you have suhosin installed?

to the roundcube maintainers: do you plan an upload to bpo? I have a backport 
ready (well, needs testing, but I'm about to do this) which I could upload...


regards,
	Holger
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part.
Url : http://lists.alioth.debian.org/pipermail/pkg-roundcube-maintainers/attachments/20090115/f0b7b12a/attachment.pgp 


More information about the Pkg-roundcube-maintainers mailing list