David Maciejak noticed that webcalendar, a PHP-based multi-user calendar, returns different error messages on login attempts for an invalid password and a non-existing user, allowing remote attackers to gain information about valid usernames.
The old stable distribution (woody) does not contain a webcalendar package.
For the stable distribution (sarge) this problem has been fixed in version 0.9.45-4sarge4.
For the unstable distribution (sid) this problem will be fixed soon.
We recommend that you upgrade your webcalendar package.
MD5 checksums of the listed files are available in the original advisory.