Debian Security Advisory

DLA-1750-1 roundup -- LTS security update

Date Reported:
07 Apr 2019
Affected Packages:
roundup
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2019-10904.
More information:

It was discovered that there was a cross-site scripting (XSS) vulnerability in the web front-end of the roundup tracking system.

  • CVE-2019-10904

    Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.

For Debian 8 Jessie, these problems have been fixed in version 1.4.20-1.1+deb8u2.

We recommend that you upgrade your roundup packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS