Thanks for the patch! Since You seem to be in the know: the release notes state 'There was also an undisclosed potential XSS vulnerability in the default exception handler (unused by default)'...does this mean the default exception handler is not used by default? Is 'default exception handler' just a name here?
As I am only the packager for Fedora, please contact upstream for security-related questions.
... and please login and leave karma here if you are happy with the release. Thank you!
"Thanks for the patch!" was referring to the patch for both XSS issues someone with a name similar to Yours submitted to PHPMailer, sorry for the confusion. Can't really test Fedora environments. The question was meant to be a more general one and I chose the wrong means of communication. Cheers!
This update has been submitted for testing by monnerat.
Thanks for the patch! Since You seem to be in the know: the release notes state 'There was also an undisclosed potential XSS vulnerability in the default exception handler (unused by default)'...does this mean the default exception handler is not used by default? Is 'default exception handler' just a name here?
As I am only the packager for Fedora, please contact upstream for security-related questions. ... and please login and leave karma here if you are happy with the release. Thank you!
"Thanks for the patch!" was referring to the patch for both XSS issues someone with a name similar to Yours submitted to PHPMailer, sorry for the confusion. Can't really test Fedora environments. The question was meant to be a more general one and I chose the wrong means of communication. Cheers!
This update has been pushed to testing.
Thank for patch.
This update has been submitted for stable by bodhi.
This update has been pushed to stable.