Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu,  2 Oct 2014 13:05:13 -0400 (EDT)
From: cve-assign@...re.org
To: hanno@...eck.de
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com
Subject: Re: CVE request: Mediawiki before 1.19.20, 1.22.12, 1.23.5 XSS through CSS

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-October/000163.html
> https://bugzilla.wikimedia.org/show_bug.cgi?id=70672
> (bug 70672) SECURITY: OutputPage: Remove separation of css and js module allowance.
> https://gerrit.wikimedia.org/r/#/c/164271/

> No longer segment module origin allowance

It seems best to assign only one CVE ID for the availability of CSS
in an apparently unintended context, with resultant impacts of both
XSS and UI redressing. Use CVE-2014-7295.


> While at it, also remove the ability to set the module allowance directly.

This change seems to be about eliminating unused and possibly
confusing functionality, not a separate vulnerability fix.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJULYVrAAoJEKllVAevmvms9wMH/0z2JxQOGiKWh6m7opKgeBEK
Z/9hLV0dmmLdXGnBo2o3HK/J0h1bYklT6+TEdQ1ESJ4EIHlejB7WsUnQY4XlSlzA
LtqFxRIBhbwVOdv+UGgdZXfNGaPoMflZqa1KSYa6vb9rIxoc3CPglM/59qSc6XCN
3Xr3mu8E9fbNT7YsZeatVhzxUh6QYHJ5JpOx7z/xiwGNqZfDqqb/eh4p70FcVPY6
bsykRXmmOwLIujsn47gSCW+g383F4vTFj7AyhIDahZXOWbm4hwJJWG6mi/MWsd3L
/nIfzN6UQfSu6EFuMLDg1+/qfJPWi9kzal/XtTG3zu54DKRqedn5UZ/EdxzrbGE=
=iYhQ
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.