|
Message-ID: <20150116080552.GA8782@kludge.henri.nerv.fi> Date: Fri, 16 Jan 2015 10:05:52 +0200 From: Henri Salo <henri@...v.fi> To: oss-security@...ts.openwall.com Subject: Re: CVE-Request -- CMS b2evolution v.5.2.0 -- Reflecting XSS vulnerability in filemanager functionality -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Thu, Jan 15, 2015 at 04:44:39PM -0500, Daniel Kahn Gillmor wrote: > An attacker could take this signed message, and replay it "From" you > with a changed subject line to try to indicate that you think some other > bug was fixed in some other piece of software, version 5.2.1. I'll be more careful in the future with automatic PGP signing. :) - -- Henri Salo -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlS4xmAACgkQXf6hBi6kbk9D0gCfeWLTaJkV5FB+Px9hWQBTbf4l Q0IAn31Gg1Tve0qNoA7cut3HhGIkf8L+ =v7tU -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.