|
Message-ID: <20130720071344.GA13185@eldamar.local> Date: Sat, 20 Jul 2013 09:13:44 +0200 From: Salvatore Bonaccorso <carnil@...ian.org> To: oss-security@...ts.openwall.com Subject: CVE Request: XSS in smokeping / start and end time fields not filtered Hi Kurt There is another XSS fix which was done after the 2.6.9 release for smokeping. In [1] Steven Chamberlain pointed out that in 2.6.9 upstrem the "start" and "end" time fields are still not filtered. Tobi Oetiker fixed this in a commit following the 2.6.9 release at [2]. But this version is no yet released. [1] http://bugs.debian.org/659899#67 [2] https://github.com/oetiker/SmokePing/commit/bad9f9c28f0939b269f90072aa4cf41f20f15563 Does this also needs a separate CVE, as a subsequent fix to the 2.6.9 release? Regards, Salvatore
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.