[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Sat, 7 Nov 2009 19:04:49 +0100
From: Alex Legler <a3li@...too.org>
To: oss-security@...ts.openwall.com
Cc: jmm@...til.org, "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE Request - Asterisk (AST-2009-008.html)
On Sat, 7 Nov 2009 18:08:55 +0100, Moritz Muehlenhoff <jmm@...til.org>
wrote:
> Jan Lieskovsky wrote:
> > The second issue (b,) already got an CVE id of CVE-2008-7220.
> >
> > b, Cross-site AJAX request vulnerability (CVE-2008-7220)
> > http://downloads.asterisk.org/pub/security/AST-2009-009.html
>
> This seems to be a mistake; CVE-2008-7220 already identifies a
> prototypejs issue.
>
This is correct. Asterisk ships a copy of prototype.js.
From the Asterisk advisory:
> Asterisk includes a demonstration AJAX based manager interface,
> ajamdemo.html which uses the prototype.js framework.
Alex
[ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ