Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20130720071344.GA13185@eldamar.local>
Date: Sat, 20 Jul 2013 09:13:44 +0200
From: Salvatore Bonaccorso <carnil@...ian.org>
To: oss-security@...ts.openwall.com
Subject: CVE Request: XSS in smokeping / start and end time fields not
 filtered

Hi Kurt

There is another XSS fix which was done after the 2.6.9 release for
smokeping.

In [1] Steven Chamberlain pointed out that in 2.6.9 upstrem the
"start" and "end" time fields are still not filtered.

Tobi Oetiker fixed this in a commit following the 2.6.9 release at
[2]. But this version is no yet released.

 [1] http://bugs.debian.org/659899#67
 [2] https://github.com/oetiker/SmokePing/commit/bad9f9c28f0939b269f90072aa4cf41f20f15563

Does this also needs a separate CVE, as a subsequent fix to the 2.6.9
release?

Regards,
Salvatore

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.