Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Sat, 7 Nov 2009 19:04:49 +0100
From: Alex Legler <a3li@...too.org>
To: oss-security@...ts.openwall.com
Cc: jmm@...til.org, "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE Request - Asterisk (AST-2009-008.html)

On Sat, 7 Nov 2009 18:08:55 +0100, Moritz Muehlenhoff <jmm@...til.org>
wrote:

> Jan Lieskovsky wrote:
> > The second issue (b,) already got an CVE id of CVE-2008-7220.
> > 
> > b, Cross-site AJAX request vulnerability (CVE-2008-7220)
> >    http://downloads.asterisk.org/pub/security/AST-2009-009.html
> 
> This seems to be a mistake; CVE-2008-7220 already identifies a
> prototypejs issue.
> 

This is correct. Asterisk ships a copy of prototype.js.

From the Asterisk advisory:
> Asterisk includes a demonstration AJAX based manager interface,
> ajamdemo.html which uses the prototype.js framework. 

Alex


[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ