oss-sec mailing list archives

Re: Re: ADOdb PDO driver: incorrect quoting may allow SQL injection


From: Anonymous <dregad () mantisbt org>
Date: Wed, 14 Sep 2016 11:03:34 +0200

Andreas Stieger <astieger () suse com> wrote:

Hi Andreas

Many thanks for your reply. 

I noticed that in your original e-mail to this list, you did not cc
cve-assign.

That's true, but I never did in the past, as this mailing list is (or was?)
monitored by mitre, so posting here has been sufficient until now. 

Furthermore in this case I was not quite certain that a CVE was actually
required for this, so I was kind of hoping for guidance. 

Also note that there are new procedures, including a request
form, in addition to the previous recommendation to contact a CNA
https://cve.mitre.org/cve/request_id.html

I was not aware of that, thanks for the heads up. Will follow these
guidelines and use the form in the future. 

Cheers
Damien





Current thread: