oss-sec mailing list archives

Re: CVE Status Clarification / Request -- kadu: Stored XSS by parsing contact's status and sms messages in history


From: Kurt Seifried <kseifried () redhat com>
Date: Mon, 27 Feb 2012 09:32:40 -0700

On 02/27/2012 03:05 AM, Jan Lieskovsky wrote:
Hello Mariusz, Kurt, Steve, vendors,

  [1] though https://bugzilla.novell.com/show_bug.cgi?id=749036#c0
  mentions CVE identifier has been already requested for this:

  "The bug still doesn't have CVE number but will have in near future."

I can only assume they requested one directly from Mitre. Steve, is this
the case? If not I'll assign one.



-- 
Kurt Seifried Red Hat Security Response Team (SRT)


Current thread: