[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] CVE request: Struts2 xsltResult local code execution flaw
From:       Kurt Seifried <kseifried () redhat ! com>
Date:       2012-03-28 14:54:05
Message-ID: 4F73260D.40205 () redhat ! com
[Download RAW message or body]

On 03/27/2012 11:29 PM, David Jorm wrote:
> A local code execution flaw has been identified in Struts2. I cannot find a CVE ID for it anywhere.
> 
> Original report: http://seclists.org/bugtraq/2012/Mar/110
> OSVDB: http://osvdb.org/80547
> X-Force: http://xforce.iss.net/xforce/xfdb/74319
> 
> Thanks

Please use CVE-2012-1592 for this issue.

-- 
Kurt Seifried Red Hat Security Response Team (SRT)
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic