Debian Security Advisory DSA 953-1 (flyspray)

Summary
The remote host is missing an update to flyspray announced via advisory DSA 953-1. Several cross-site scripting vulnerabilities have been discovered in flyspray, a lightweight bug tracking system, which allows attackers to insert arbitary script code into the index page. The old stable distribution (woody) does not contain flyspray.
Solution
For the stable distribution (sarge) this problem has been fixed in version 0.9.7-2.1. For the testing (etch) and unstable distribution (sid) this problem has been fixed in version 0.9.8-5. We recommend that you upgrade your flyspray package. https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20953-1