Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20150116080552.GA8782@kludge.henri.nerv.fi>
Date: Fri, 16 Jan 2015 10:05:52 +0200
From: Henri Salo <henri@...v.fi>
To: oss-security@...ts.openwall.com
Subject: Re: CVE-Request -- CMS b2evolution v.5.2.0 --
 Reflecting XSS vulnerability in filemanager functionality

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thu, Jan 15, 2015 at 04:44:39PM -0500, Daniel Kahn Gillmor wrote:
> An attacker could take this signed message, and replay it "From" you
> with a changed subject line to try to indicate that you think some other
> bug was fixed in some other piece of software, version 5.2.1.

I'll be more careful in the future with automatic PGP signing. :)

- -- 
Henri Salo
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlS4xmAACgkQXf6hBi6kbk9D0gCfeWLTaJkV5FB+Px9hWQBTbf4l
Q0IAn31Gg1Tve0qNoA7cut3HhGIkf8L+
=v7tU
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.