oss-sec mailing list archives

Re: CVE request: zonecheck


From: "Steven M. Christey" <coley () linus mitre org>
Date: Mon, 7 Jun 2010 11:03:29 -0400 (EDT)


On Tue, 1 Jun 2010, Josh Bressers wrote:

Hi,

there is a cross-scripting issue in zonecheck's CGI, up to version
2.1.0
(fixed upstream in 2.1.1):

  http://bugs.debian.org/583290
  https://savannah.nongnu.org/bugs/?29967
  http://www.xssed.com/mirror/61096/


Please use CVE-2010-2052

I inadvertently assigned a duplicate, CVE-2010-2155, after this initial assignment. Since CVE-2010-2155 is already widespread based on Google counts, we should keep it, and reject the CVE-2010-2052 that was assigned by Josh.

Sorry about that, my fault...

- Steve


Current thread: