|
|
Message-ID: <146849069.119412.1304965783884.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Mon, 9 May 2011 14:29:43 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: coley@...re.org
Subject: Re: CVE request : client-side file creation via XSLT
in Webkit
----- Original Message -----
> The bug was opened on January 18 :
> https://bugs.webkit.org/show_bug.cgi?id=52688 (restricted)
>
> A patch is available since February 20 :
> http://trac.webkit.org/changeset/79159 (public)
>
> Given some recent mail exchanges with Apple, they still not have
> affected a CVE to this issue. Could you please allocate one, in order
> for me to have an easier job communicating with the numerous impacted
> vendors (many Linux distributions, RIM, Maxthon, ...) ?
>
I don't see a CVE id in the upstream bug, so I'll risk assigning an ID.
Use CVE-2011-1774
Thanks.
--
JB
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.