Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <DDFFF4D8159CAA4881A60FDDAEA4E5482A712334A7@GVW0671EXC.americas.hpqcorp.net>
Date: Sat, 19 Mar 2011 18:45:57 +0000
From: "Menkhus, Mark (GSE Security HP SSRT)" <mark.menkhus@...com>
To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>,
	"aungkhant@...g.net" <aungkhant@...g.net>
Subject: RE: CVE Request: HP System Management Homepage(SMH)
 | Open URL Redirection

Hi,

SMH is not FOSS. The CVE assigned to this issue is CVE-2010-1586, and the
security bulletin is at
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c0251
8794 which was published a while back  

Something fell through the cracks and we did not notify the reporter.
Apologies to Aung Khant.

Thanks,
Mark Menkhus
Hewlett Packard Software Security Response Team
> -----Original Message-----
> From: Mike O'Connor [mailto:mjo@...o.mi.org]
> Sent: Friday, March 18, 2011 1:05 PM
> To: oss-security@...ts.openwall.com
> Subject: Re: [oss-security] CVE Request: HP System Management
> Homepage(SMH) | Open URL Redirection
> 
> :Discovered by
> :Aung Khant (aungkhant<@>yehg.net)
> :YGN Ethical Hacker Group, Myanmar
> :http://yehg.net/
> :
> :Product:
> :HP System Management Homepage
> 
> Is this open source software?
> 
> --
>  Michael J. O'Connor
> mjo@...o.mi.org
>  =--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==-
> -==--=
> "Nothing in fine print is ever good news.                        -Andy
> Rooney

Download attachment "smime.p7s" of type "application/x-pkcs7-signature" (4916 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.