Hi,
torrentflux recently had several vulnerabilities due to not properly
sanitizing user input [1,2]. I think this is a candidate for an audit
or/and exclusion from etch.
Does anyone have time for an audit?
Cheers,
Stefan
[1]
http://security-tracker.debian.net/tracker/source-package/torrentflux
[2] After a quick check, I found an issue with the 'announce'
parameter in maketorrent.php.
pgpK8pRbKyHld.pgp
Description: PGP signature
|