Re: Incomplete OpenPKG reference in apache_log_injection.nasl
"Pavel Kankovsky" <[email protected]>
| Newsgroups | gmane.comp.security.nessus.devel |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 5 Jul 2004, Jan Fredrik Leversund wrote: > script_xref(name:"OpenPKG-SA", value:"OpenPKG-SA-2004.021-apache"); > > OpenPKG uses a weird format for their security advisory keys; they > include the name of the package in question. Do they? <snip> Subject: [OpenPKG-SA-2004.026] OpenPKG Security Advisory (apache) [...] ________________________________________________________________________ OpenPKG Security Advisory The OpenPKG Project http://www.openpkg.org/security.html http://www.openpkg.org [email protected] [email protected] OpenPKG-SA-2004.026 27-May-2004 ________________________________________________________________________ </snip> Perhaps they add an extra suffix to a URL when they publish advisories on their web? Shame on them...if they really do that. Anyway, the official advisory id appears to be "OpenPKG-SA-200X-YZW" without the package name. And I think Nessus should use this id and nothing else. --Pavel Kankovsky aka Peak [ Boycott Microsoft--http://www.vcnet.com/bms ] "Resistance is futile. Open your source code and prepare for assimilation." _______________________________________________ Nessus-devel mailing list [email protected] http://mail.nessus.org/mailman/listinfo/nessus-devel