Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <201309011623.r81GNkPN007293@linus.mitre.org>
Date: Sun, 1 Sep 2013 12:23:46 -0400 (EDT)
From: cve-assign@...re.org
To: hanno@...eck.de
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com
Subject: Re: CVE request: serendipity before 1.7.3 XSS

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> Serendipity blog software contains an XSS in the shipped
> htmlarea-code for spell checking.
> 
> http://osvdb.org/87395
> http://blog.s9y.org/archives/250-Serendipity-1.7.3-released.html
> https://github.com/s9y/Serendipity/commit/d7dbe7757371c7f25a39463d1b924604785ae475

Use CVE-2013-5670.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJSI2aJAAoJEGvefgSNfHMdbWgH/1gF/pZXsQ6sHgUg0UXHc5GZ
0qZUQS2zmlKoNGl/hboXfNjOIv6VwsJ6g0IHMOKfg7NCyfeq33ELTXd7V1fQxAx+
9zeXWHrnLVmK/QIksycsZFACqGcws6eJhEDCNUL2u9l4yKkSmwCF7/LnGaBDOOr7
H7QcA3pRJnvxlN8Ps8sOUaWgB0GJr6Bjo7N6Z/e7muJJlz/fbqX40oF/kLopRkba
AiCif4q0PwR8tmGoU2lk8a8ZpVQtP3o/N22Lke/8qmio81fWPos4bwn8obRBygrp
p3wPJq+v+zk8bmBCdxnXWN9ECwxzC5BEXm+WbAq6G9rVyzzjrN3Q9Dj05ygJiJg=
=Cvft
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.