From billk at cts.com Wed Jan 7 06:41:11 2009 From: billk at cts.com (Bill Kelly) Date: Wed, 7 Jan 2009 03:41:11 -0800 Subject: [Nitro] Nitro security vulnerability Message-ID: <2FDE3F1A23F242F3945795968C2F6D4A@gonzo> Hi, I'm not sure what the protocol is for reporting vulnerabilities, so I won't say anything explict in this email. A security company tested our site and found a type of malformed URL that when handled by Nitro allows reading arbitrary files on the host system. I don't have a patch yet, but I'll begin debugging the issue tomorrow morning. When I do have a patch, what's the proper way for me to report the issue? Regards, Bill From george.moschovitis at gmail.com Wed Jan 7 06:57:05 2009 From: george.moschovitis at gmail.com (George Moschovitis) Date: Wed, 7 Jan 2009 13:57:05 +0200 Subject: [Nitro] Nitro security vulnerability In-Reply-To: <2FDE3F1A23F242F3945795968C2F6D4A@gonzo> References: <2FDE3F1A23F242F3945795968C2F6D4A@gonzo> Message-ID: Please send me more details privately. thank you, George. On Wed, Jan 7, 2009 at 1:41 PM, Bill Kelly wrote: > Hi, > > I'm not sure what the protocol is for reporting vulnerabilities, > so I won't say anything explict in this email. > > A security company tested our site and found a type of malformed > URL that when handled by Nitro allows reading arbitrary files > on the host system. > > I don't have a patch yet, but I'll begin debugging the issue > tomorrow morning. > > When I do have a patch, what's the proper way for me to report > the issue? > > > Regards, > > Bill > > > _______________________________________________ > Nitro-general mailing list > Nitro-general at rubyforge.org > http://rubyforge.org/mailman/listinfo/nitro-general > -- gmosx.com -------------- next part -------------- An HTML attachment was scrubbed... URL: