oss-sec mailing list archives

Re: CVE request - asterisk, python-markdown, jetty, kde


From: Mark J Cox <mjc () redhat com>
Date: Thu, 29 Oct 2009 15:59:35 +0000 (GMT)

= asterisk =
Unauthorized calls allowed on prohibited networks in asterisk
Reference:
Advisory: http://downloads.asterisk.org/pub/security/AST-2009-007.html

CVE-2009-3723

= python-markdown =
Multiple XSS attack vectors
References:
http://code.google.com/p/python-markdown2/issues/detail?id=30
http://code.google.com/p/python-markdown2/issues/detail?id=29
http://secunia.com/advisories/37142/

Since all XSS type CVE-2009-3724 for all

= kde =
Multiple missing input sanity checks in KDE
Reference:
http://www.ocert.org/advisories/ocert-2009-015.html

oCERT said names have already been requested, not allocating.

= jetty =
Multiple vulnerabilities in jetty
Reference:
http://www.ush.it/team/ush/hack-jetty6x7x/jetty-adv.txt

Multiple issues will need more work to allocate; deferred.

Mark


Current thread: