Date: Sat, 21 Feb 2015 10:07:39 -0500 (EST) From: cve-assign@...re.org To: paul@...tisforge.org Cc: cve-assign@...re.org, oss-security@...ts.openwall.com, dregad@...tisbt.org Subject: Re: CVE request: XSS in MantisBT -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 > I'm not actually sure what "types of attacks" are blocked The vendor can expand on this if they wish. At present, the available information is this statement: In 1.3, cabacdc2 + 3d0625d8 together form at least a *partial* fix in the http://openwall.com/lists/oss-security/2015/02/16/7 post. The concept of a code change with a "partial fix" ordinarily means that at least one attack vector is blocked by that code change, such as an attack vector that relied on a specific code path that was affected by the change. - -- CVE assignment team, MITRE CVE Numbering Authority M/S M300 202 Burlington Road, Bedford, MA 01730 USA [ PGP key available through http://cve.mitre.org/cve/request_id.html ] -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.14 (SunOS) iQEcBAEBAgAGBQJU6J6JAAoJEKllVAevmvmsDVIIAMVGqyQVahMFtcem3pOQym3z 2u2WtvlwiAxQ9vvmFJvyuYzKWvjqXI17M30G4WhweriLtG/Xoqg2u4cQL5TC7hUP bVAD1yVnoGBEOOAUXZtsNg6Od79IMRkpOtdcdgKislsN7BZuwnXKkek8TNvjZtvz wL9lfwvjKkusoqohl7GSLZ9eErB5vY1tGAruzp4gzxnQZtZGGRMcvawwUe6ptuat UIoHZzglTRfMBEEgvMy7DdhHS3nc9YBuT3tK1C6a5h/UfMjKYvZjMEe0+hicL1kH WFFpYI7Cm451KgBs9JS5qVBlGLRFDa2Tt1sIZZ9q7+suYSSa6NjZOLLO0BMCpeg= =lsDW -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.