oss-sec mailing list archives

RE: CVE Request: HP System Management Homepage(SMH) | Open URL Redirection


From: "Menkhus, Mark (GSE Security HP SSRT)" <mark.menkhus () hp com>
Date: Sat, 19 Mar 2011 18:45:57 +0000

Hi,

SMH is not FOSS. The CVE assigned to this issue is CVE-2010-1586, and the
security bulletin is at
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c0251
8794 which was published a while back  

Something fell through the cracks and we did not notify the reporter.
Apologies to Aung Khant.

Thanks,
Mark Menkhus
Hewlett Packard Software Security Response Team
-----Original Message-----
From: Mike O'Connor [mailto:mjo () dojo mi org]
Sent: Friday, March 18, 2011 1:05 PM
To: oss-security () lists openwall com
Subject: Re: [oss-security] CVE Request: HP System Management
Homepage(SMH) | Open URL Redirection

:Discovered by
:Aung Khant (aungkhant<@>yehg.net)
:YGN Ethical Hacker Group, Myanmar
:http://yehg.net/
:
:Product:
:HP System Management Homepage

Is this open source software?

--
 Michael J. O'Connor
mjo () dojo mi org
 =--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==--==-
-==--=
"Nothing in fine print is ever good news.                        -Andy
Rooney

Attachment: smime.p7s
Description:


Current thread: