Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 26 Jul 2011 15:32:26 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: justin@...irish.net, coley <coley@...re.org>
Subject: Re: CVE request: Drupal Data-module multiple
 vulnerabilities



----- Original Message -----
> These issues does not have CVE-identifiers. Could we get one?
> 
> http://seclists.org/fulldisclosure/2011/Feb/219
> 
> I asked from Justin Klein Keane and he wasn't aware of CVE-identifier.
> I think this needs identifier even this is an alpha release as this
> module is used by some production instances. If I am correct two
> identifiers should be enough. One for XSS and another for SQL
> injections.
> 
> Discussion about the issue: http://drupal.org/node/1056470
> 

Please use CVE-2011-2714 for the XSS.

CVE-2011-2715 is for the SQL injection.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.