|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2005-3425: gnump3d cross-site-scripting and directory traversal | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Thomas Biege <thomas> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P5 - None | CC: | lnussel, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| Whiteboard: | CVE-2005-3425: CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: |
gnump3d-xss.diff
gnump3d-dot-dot.diff |
||
|
Description
Thomas Biege
2005-10-19 10:05:10 UTC
Created attachment 54722 [details]
gnump3d-xss.diff
Created attachment 54723 [details]
gnump3d-dot-dot.diff
*** Bug 130963 has been marked as a duplicate of this bug. *** According to this mail CRD is tomorrow. Maintenance-Tracker-2689 ping Don't forget that when we get bad statistics from lwn.net. CVE-2005-3424 CVE-2005-3425 CVE-2005-3122 has been rejected. don't use. one testcase is http://localhost:8888/etc/passwd?theme=../../../../ CVE-2005-3349 - /tmp issue CVE-2005-3355 - directory traversal via theme parameter packages released CVE-2005-3425: CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) |