Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20121010051333.GA5455@kludge.henri.nerv.fi>
Date: Wed, 10 Oct 2012 08:13:33 +0300
From: Henri Salo <henri@...v.fi>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: Joomla two XSS vulnerabilities
 fixed in 2.5.7

On Tue, Oct 09, 2012 at 10:58:11PM -0600, Kurt Seifried wrote:
> I'm wondering,there seems to be some gaps in Joomla CVE assignments,
> are there other Joomlas that need CVEs as well?

Probably. I have been requesting these once I notice CVE is missing. It would help a lot if Joomla would put CVEs to advisories once assigned. This list also contains lots of issues, which needs verification and coordination: http://docs.joomla.org/Vulnerable_Extensions_List

Usually Joomla does not reply to emails sent to address security@j<snip>.org (other than autoreply).

- Henri Salo

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.