Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sat, 20 Jul 2013 09:13:44 +0200
From: Salvatore Bonaccorso <>
Subject: CVE Request: XSS in smokeping / start and end time fields not

Hi Kurt

There is another XSS fix which was done after the 2.6.9 release for

In [1] Steven Chamberlain pointed out that in 2.6.9 upstrem the
"start" and "end" time fields are still not filtered.

Tobi Oetiker fixed this in a commit following the 2.6.9 release at
[2]. But this version is no yet released.


Does this also needs a separate CVE, as a subsequent fix to the 2.6.9


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.