Package: mono
Severity: important
Tags: security

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for mono.

CVE-2008-3906[0]:
| CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows
| remote attackers to inject arbitrary HTTP headers and conduct HTTP
| response splitting attacks via CRLF sequences in the query string.

If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.

The suse bugreport and some additional information can be found here[1].

Cheers
Steffen

For further information see:

[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3906
    http://security-tracker.debian.net/tracker/CVE-2008-3906
[1] https://bugzilla.novell.com/show_bug.cgi?id=418620



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to