Re: Advisory description text

2008-01-08 Thread Moritz Muehlenhoff
Adam Majer wrote: > Moritz Muehlenhoff wrote: >> CVE-2007-3382 >> >> It was discovered that single quotes (') in cookies were treated >> as a delimiter, which could lead to an information leak. >> >> CVE-2007-3385 >> >> It was discovered that the character sequence \" in cookies was

Re: Advisory description text

2008-01-07 Thread Rob Sims
On Mon, Jan 07, 2008 at 10:20:40PM +0100, Christoph Ulrich Scholler wrote: > Hi, > > On 07.01. 13:54, Adam Majer wrote: > > Moritz Muehlenhoff wrote: > > > CVE-2007-3382 > > > > > > It was discovered that single quotes (') in cookies were treated > > > as a delimiter, which could lead to

Re: Advisory description text

2008-01-07 Thread Christoph Ulrich Scholler
Hi, On 07.01. 13:54, Adam Majer wrote: > Moritz Muehlenhoff wrote: > > CVE-2007-3382 > > > > It was discovered that single quotes (') in cookies were treated > > as a delimiter, which could lead to an information leak. > > > > CVE-2007-3385 > > > > It was discovered that the charact

Advisory description text

2008-01-07 Thread Adam Majer
Moritz Muehlenhoff wrote: > CVE-2007-3382 > > It was discovered that single quotes (') in cookies were treated > as a delimiter, which could lead to an information leak. > > CVE-2007-3385 > > It was discovered that the character sequence \" in cookies was > handled incorrectly, w