Mageia Bugzilla – Attachment 937 Details for
Bug 2736
BackupPC 3.2.1 fixes cross site scripting
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Requests
|
Help
|
Log In
[x]
|
New Account
|
Forgot Password
[patch]
Debian security patch adapted to new source of EditConfig.pm
BackupPC-3.2.1-CVE-2011-xxx.diff (text/plain), 424 bytes, created by
Juergen Harms
on 2011-10-11 14:54:39 CEST
(
hide
)
Description:
Debian security patch adapted to new source of EditConfig.pm
Filename:
MIME Type:
Creator:
Juergen Harms
Created:
2011-10-11 14:54:39 CEST
Size:
424 bytes
patch
obsolete
>--- lib/BackupPC/CGI/EditConfig.pm 2011-04-25 05:31:55.000000000 +0200 >+++ lib/BackupPC/CGI/EditConfig.pm.JH 2011-10-11 07:12:05.570037764 +0200 >@@ -452,4 +452,8 @@ > # available per-host settings. > # >+ >+ # Debian: ClientNameAlias is too dangerous, disable it >+ $bpc->{Conf}{CgiUserConfigEdit}{ClientNameAlias} = 0; >+ > foreach my $m ( keys(%ConfigMenu) ) { > my $enabled = 0;
--- lib/BackupPC/CGI/EditConfig.pm 2011-04-25 05:31:55.000000000 +0200 +++ lib/BackupPC/CGI/EditConfig.pm.JH 2011-10-11 07:12:05.570037764 +0200 @@ -452,4 +452,8 @@ # available per-host settings. # + + # Debian: ClientNameAlias is too dangerous, disable it + $bpc->{Conf}{CgiUserConfigEdit}{ClientNameAlias} = 0; + foreach my $m ( keys(%ConfigMenu) ) { my $enabled = 0;
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 2736
:
936
| 937 |
938
|
946