Please do not reply directly to this email. All additional comments should be made in the comments box of this bug report. Summary: multiple vulnerabilities in thttpds htpasswd utility https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=191095 ------- Additional Comments From ville.skytta@xxxxxx 2006-07-03 13:35 EST ------- One more thing to look into: the Debian testing security team has marked both these CVE's fixed in their 2.23beta1-2.4, perhaps a patch could be "borrowed" from there: http://svn.debian.org/wsvn/secure-testing/data/CVE/list?op=file&rev=0&sc=0 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=253816 http://ftp.debian.org/debian/pool/main/t/thttpd/thttpd_2.23beta1-4.diff.gz -- Configure bugmail: https://bugzilla.redhat.com/bugzilla/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug, or are watching someone who is.