Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sun, 11 Aug 2013 21:06:46 -0700
From: Forest Monsen <forest.monsen@...il.com>
To: Henri Salo <henri@...v.fi>
Cc: oss-security@...ts.openwall.com, Kurt Seifried <kseifried@...hat.com>
Subject: Re: CVE request for Drupal contributed modules

Good, thanks Henri.


On Sat, Aug 10, 2013 at 12:38 AM, Henri Salo <henri@...v.fi> wrote:

> On Fri, Aug 09, 2013 at 10:02:59PM -0600, Kurt Seifried wrote:
> > On 08/09/2013 05:29 PM, Forest Monsen wrote:
> > > Hi there,
> > >
> > > I'd like to request CVE identifiers for...
> > >
> > > SA-CONTRIB-2013-061 - Flippy - Access Bypass
> > > https://drupal.org/node/2054701
> > >
> > > SA-CONTRIB-2013-062 - RESTful Web Services (RESTWS) - Access
> > > Bypass https://drupal.org/node/2059603
> > >
> > > SA-CONTRIB-2013-063 - Authenticated User Page Caching (Authcache)
> > > - Information Disclosure https://drupal.org/node/2059589
> > >
> > > SA-CONTRIB-2013-064 - Persona - Cross site request forgery (CSRF)
> > > https://drupal.org/node/2059599
> > >
> > > SA-CONTRIB-2013-065 - Organic Groups - Access Bypass
> > > https://drupal.org/node/2059765
> > >
> > > SA-CONTRIB-2013-066 - Monster Menus - Multiple Vulnerabilities
> > > (Looks like two here: XSS, and an Access Bypass vuln)
> > > https://drupal.org/node/2059823
> > >
> > > Thanks!
> > >
> > > Best, Forest
> > >
> >
> > Yup
> >
> > CVE-2013-4224 SA-CONTRIB-2013-061 - Flippy - Access Bypass
> >
> > CVE-2013-4225 SA-CONTRIB-2013-062 - RESTful Web Services (RESTWS) -
> > Access Bypass
> >
> > CVE-2013-4226 SA-CONTRIB-2013-063 - Authenticated User Page Caching
> > (Authcache) -Information Disclosure
> >
> > CVE-2013-4227 SA-CONTRIB-2013-064 - Persona - Cross site request
> > forgery (CSRF)
> >
> > CVE-2013-4228 SA-CONTRIB-2013-065 - Organic Groups - Access Bypass
> >
> > CVE-2013-4229 SA-CONTRIB-2013-066 - Monster Menus XSS
> >
> > CVE-2013-4230 SA-CONTRIB-2013-066 - Monster Menus Access Bypass
>
> CVE-2013-4187 has been assigned already for SA-CONTRIB-2013-061[1].
> CVE-2013-4224 should be REJECTED if I am correct, thanks.
>
> 1: http://www.openwall.com/lists/oss-security/2013/08/01/1
>
> ---
> Henri Salo
>

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.