Follow us on Twitter or via RSS feeds with tweets or complete announcement texts or excerpts
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 09 May 2011 16:11:12 +0200
From: Nicolas Grégoire <nicolas.gregoire@...rri.fr>
To: oss-security@...ts.openwall.com
Subject: CVE request : client-side file creation via XSLT in Webkit


The bug was opened on January 18 :
https://bugs.webkit.org/show_bug.cgi?id=52688 (restricted)

A patch is available since February 20 :
http://trac.webkit.org/changeset/79159 (public)

Given some recent mail exchanges with Apple, they still not have
affected a CVE to this issue. Could you please allocate one, in order
for me to have an easier job communicating with the numerous impacted
vendors (many Linux distributions, RIM, Maxthon, ...) ?

Regards,
Nicolas Grégoire

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ