oss-sec mailing list archives

Re: CVE request for Drupal contributed modules


From: Kurt Seifried <kseifried () redhat com>
Date: Mon, 04 Feb 2013 19:14:56 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 02/04/2013 10:24 AM, Forest Monsen wrote:
Hi there,

Here's a request for CVE identifiers for several issues with
Drupal contributed modules. Thank you Kurt.

SA-CONTRIB-2013-011 - email2image - Access Bypass - Unsupported 
http://drupal.org/node/1903264

Please use CVE-2013-0257 for this issue.

SA-CONTRIB-2013-012 - Google Authenticator login - Access Bypass 
http://drupal.org/node/1903282

Please use CVE-2013-0258 for this issue.

SA-CONTRIB-2013-013 - Boxes - Cross site scripting (XSS) 
http://drupal.org/node/1903300

Please use CVE-2013-0259 for this issue.

SA-CONTRIB-2013-014 - Drush Debian Packaging - Information
Disclosure - Unsupported http://drupal.org/node/1903324

Please use CVE-2013-0260 for this issue.


Forest


- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (GNU/Linux)

iQIcBAEBAgAGBQJREGsfAAoJEBYNRVNeJnmTSQgQAJp2INAuP0EYBBuLFFNT05aM
a6WcCQ1qhu5Bg7E631YHoqMkHY3G1ozFIlBk30L10cXDYp9D7H7/He+Qgb0plJ7X
W9HeQVx5Hz9d3IfhlGq8Ih4Buw0UmpQmvGnmMvRgjmdP44r/uuCbl+8Q/aj20ivh
0z8ZnKZtELDucyUdxuHprn6YujHSIuBUIJcjtftoiaCQpnt9PI4eS4xXaysZaOdc
oBW55G2fYUvLS2kgWZQvYFIlK6nXd0nGMfXyHnnr8Jv0J2v2+iDBd2LJ880kLAyB
YC3jmMtfJqX+eQw3AGCCn9pscJWfbrK4Z+tlgHilVArjORS/Pmy3M5jrIOAj9tL2
ls9+Ej2KHmYNm5kZstVpgfYbPRoSY/xcZY6Aq/RdISnvUJy+Q4mBKmGs4iQn99lN
M8aeIs8QszxaaLcywJkfShfGVEi1ix/hChtAxN2QvuNAfeFCTVX3B9EuH8VoqfGF
T5hokqbi26Ifsnex6Gd40pd/40PouIskZD/l9rz7sp+4POVPszqEhy22kPQ6TINx
RaW2Tdhk6XnGBiQB2QMsKoNyBnJIrS/im+6Noa55MLUxvR9ASdLJ8ij4wHAtNswN
G+vBwnelaSgt3hPpIqRkk7t2MLojKr2rfSmtkj2hg4ru0d6aJFfyRNY6Rax3HrYY
vDoySkJDJgBjvvWTGXuH
=7L+6
-----END PGP SIGNATURE-----


Current thread: