Debian Security Advisory DSA 1486-1 (gnatsweb)

Summary
The remote host is missing an update to gnatsweb announced via advisory DSA 1486-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201486-1
Insight
r0t discovered that gnatsweb, a web interface to GNU GNATS, did not correctly sanitize the database parameter in the main CGI script. This could allow the injection of arbitrary HTML, or javascript code. For the stable distribution (etch), this problem has been fixed in version 4.00-1etch1. We recommend that you upgrade your gnatsweb package.