BlogoText / blogotext

A little more than a lightweight SQLite Blog-Engine.
Other
137 stars 30 forks source link

Contact for security issue #318

Closed chb9 closed 7 years ago

chb9 commented 7 years ago

Hi,

I've found a serious security issue in BlogoText 3.7.5.

@remrem How can I contact (email) you privately?

remrem commented 7 years ago

Hi, just created : contact at blogotext.org

remrem commented 7 years ago

Hi @chb9 , I did not receive your email, did you have time to send it?

chb9 commented 7 years ago

@remrem I just sent the mail again. Did you receive it?

remrem commented 7 years ago

Yep !, My bad, mail filtering ...

Thank for this report, I take a look on it right now !

remrem commented 7 years ago

Ok, security issue confirmed. A big thank-you to you @chb9 for this issue, you rock!

I'll do my best to quickly push a fix and let the community know about the fix.

@chb9, If you plan to release this issue to the public domain, can you wait some time to let the community update theirs BlogoText ? And I think you deserve a place in CONTRIBUTORS if you want (I let you push a commit).

B4rb3rouss commented 7 years ago

I'm very curious to know more about this issue.

Thank you for reporting.

chb9 commented 7 years ago

If you plan to release this issue to the public domain, can you wait some time to let the community update theirs BlogoText ?

Of course. I will also request a CVE ID after you fix that issue.

And I think you deserve a place in CONTRIBUTORS if you want (I let you push a commit).

Thank you.

chb9 commented 7 years ago

@remrem When do you plan to fix this issue and release a new version?

remrem commented 7 years ago

@chb9 Tomorrow. Not enough time in the last few days :/

BoboTiG commented 7 years ago

@remrem do you want I take a look?

remrem commented 7 years ago

@BoboTiG I'm working on this right now ;)

remrem commented 7 years ago

Fixed version Again, thank you @chb9 ! If you need an official comment or documentation for your CVE ID request, @BoboTiG and me are here ;)

B4rb3rouss commented 7 years ago

Thank you :)

chb9 commented 7 years ago

@remrem Thank you, I've requested a CVE ID and let you know as soon as I have it.

remrem commented 7 years ago

Ok, I close this issue.

chb9 commented 7 years ago

CVE-2017-14957 has been assigned for this issue.

remrem commented 7 years ago

@chb9, thank you ;) I've just update the release description