|
Message-Id: <20141002170513.E6BBD7BC01A@smtpvmsrv1.mitre.org> Date: Thu, 2 Oct 2014 13:05:13 -0400 (EDT) From: cve-assign@...re.org To: hanno@...eck.de Cc: cve-assign@...re.org, oss-security@...ts.openwall.com Subject: Re: CVE request: Mediawiki before 1.19.20, 1.22.12, 1.23.5 XSS through CSS -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 > https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-October/000163.html > https://bugzilla.wikimedia.org/show_bug.cgi?id=70672 > (bug 70672) SECURITY: OutputPage: Remove separation of css and js module allowance. > https://gerrit.wikimedia.org/r/#/c/164271/ > No longer segment module origin allowance It seems best to assign only one CVE ID for the availability of CSS in an apparently unintended context, with resultant impacts of both XSS and UI redressing. Use CVE-2014-7295. > While at it, also remove the ability to set the module allowance directly. This change seems to be about eliminating unused and possibly confusing functionality, not a separate vulnerability fix. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJULYVrAAoJEKllVAevmvms9wMH/0z2JxQOGiKWh6m7opKgeBEK Z/9hLV0dmmLdXGnBo2o3HK/J0h1bYklT6+TEdQ1ESJ4EIHlejB7WsUnQY4XlSlzA LtqFxRIBhbwVOdv+UGgdZXfNGaPoMflZqa1KSYa6vb9rIxoc3CPglM/59qSc6XCN 3Xr3mu8E9fbNT7YsZeatVhzxUh6QYHJ5JpOx7z/xiwGNqZfDqqb/eh4p70FcVPY6 bsykRXmmOwLIujsn47gSCW+g383F4vTFj7AyhIDahZXOWbm4hwJJWG6mi/MWsd3L /nIfzN6UQfSu6EFuMLDg1+/qfJPWi9kzal/XtTG3zu54DKRqedn5UZ/EdxzrbGE= =iYhQ -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.