Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Sat, 21 Feb 2015 10:07:39 -0500 (EST)
From: cve-assign@...re.org
To: paul@...tisforge.org
Cc: cve-assign@...re.org, oss-security@...ts.openwall.com, dregad@...tisbt.org
Subject: Re: CVE request: XSS in MantisBT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> I'm not actually sure what "types of attacks" are blocked

The vendor can expand on this if they wish. At present, the available
information is this statement:

  In 1.3, cabacdc2 + 3d0625d8 together form at least a *partial* fix

in the http://openwall.com/lists/oss-security/2015/02/16/7 post. The
concept of a code change with a "partial fix" ordinarily means that at
least one attack vector is blocked by that code change, such as an
attack vector that relied on a specific code path that was affected by
the change.

- -- 
CVE assignment team, MITRE CVE Numbering Authority
M/S M300
202 Burlington Road, Bedford, MA 01730 USA
[ PGP key available through http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (SunOS)

iQEcBAEBAgAGBQJU6J6JAAoJEKllVAevmvmsDVIIAMVGqyQVahMFtcem3pOQym3z
2u2WtvlwiAxQ9vvmFJvyuYzKWvjqXI17M30G4WhweriLtG/Xoqg2u4cQL5TC7hUP
bVAD1yVnoGBEOOAUXZtsNg6Od79IMRkpOtdcdgKislsN7BZuwnXKkek8TNvjZtvz
wL9lfwvjKkusoqohl7GSLZ9eErB5vY1tGAruzp4gzxnQZtZGGRMcvawwUe6ptuat
UIoHZzglTRfMBEEgvMy7DdhHS3nc9YBuT3tK1C6a5h/UfMjKYvZjMEe0+hicL1kH
WFFpYI7Cm451KgBs9JS5qVBlGLRFDa2Tt1sIZZ9q7+suYSSa6NjZOLLO0BMCpeg=
=lsDW
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.