Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Tue, 26 Jun 2012 14:44:48 +0200
From: Jan Lieskovsky <>
To: "Steven M. Christey" <>,
        Mitre CVE assign department <>
CC:, Thomas Spura <>
Subject: CVE-2012-2639 reject request (duplicate of CVE-2011-4940)

Hello Steve, vendors,

   due the recently assigned CVE-2012-2639:

Name: CVE-2012-2639
Status: Candidate
Assigned: 20120514
Reference: CONFIRM:
Reference: JVN:JVN#51176027
Reference: URL:
Reference: JVNDB:JVNDB-2012-000063
Reference: URL:

The list_directory function in Lib/ in
SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and
2.7.x before 2.7.2 does not place a charset parameter in the
Content-Type HTTP header, which makes it easier for remote attackers
to conduct cross-site scripting (XSS) attacks against Internet
Explorer 7 via UTF-7 encoding.

Could you reject it? (as it is a duplicate of CVE-2011-4940):

Thank you && Regards, Jan.
Jan iankko Lieskovsky / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.