Jboss vulnerability

2007-02-20 Thread dexie
Just fired this off to USCERT, not pretty. Original Message Subject: jboss vulnerability From:[EMAIL PROTECTED] Date:Tue, February 20, 2007 10:54 pm To: "[EMAIL PROTECTED]" <[EMAIL PROTECTED]> Cc: &

Re: Jboss vulnerability

2007-02-20 Thread James Davis
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [EMAIL PROTECTED] wrote: > Please let me know if you need any further info - I have nfi who to > actually contact as auscert has no vulnerability reporting option and this > is a first for me... Your best starting point might be to visit http://www.r

Re: Jboss vulnerability

2007-02-20 Thread Harry Hoffman
information. Cheers, Harry [EMAIL PROTECTED] wrote: > Just fired this off to USCERT, not pretty. > > Original Message > Subject: jboss vulnerability > From:[EMAIL PROTECTED] > Date:Tue, February 20, 2007 10:54 pm

Re: Jboss vulnerability

2007-02-20 Thread Javier Antunez
not pretty. Original Message ---- Subject: jboss vulnerability From:[EMAIL PROTECTED] Date:Tue, February 20, 2007 10:54 pm To: "[EMAIL PROTECTED]" <[EMAIL PROTECTED]> Cc: "[EMA

Re: Jboss vulnerability

2007-02-21 Thread ben . dexter
Thanks for the info guys. James - I have notified Redhat (thanks again for the contact details); Harry - I forwarded your solution to USCERT (citing you as reference) as they have put this vulnerability note up : http://www.kb.cert.org/vuls/id/632656 Regards, Ben.

Re: Jboss vulnerability (AUSCERT#2007d2feb)

2007-02-21 Thread AusCERT
off to USCERT, not pretty. > > Original Message ---- > Subject: jboss vulnerability > From:[EMAIL PROTECTED] > Date:Tue, February 20, 2007 10:54 pm > To: "[EMAIL PROTECTED]" <[EMAIL PROTECTED]&