[VIM] BID 63301?

Dinesh Theerthagiri Dinesh_Theerthagiri at symantec.com
Mon Oct 28 10:47:25 CDT 2013


Thanks right , they are saying "Contexis 1.0" is vulnerable and its fixed in "Contexis 2.0". But still we are not able to find the download product. 

Can you anybody please tell, no what basics CVE will be assigned. As of my understanding goes CVE are assigned only for downloadable application.  

Thanks,
T.Dinesh

-----Original Message-----
From: vim-bounces at attrition.org [mailto:vim-bounces at attrition.org] On Behalf Of security curmudgeon
Sent: Friday, October 25, 2013 1:54 AM
To: Vulnerability Information Managers
Subject: Re: [VIM] BID 63301?
Importance: High


http://seclists.org/fulldisclosure/2013/Oct/221

Here is the disclosure for it. They are saying "1.0" is vuln, and the vendor page shows "2.0" on a box. However, all of the wording implies this is a hosted solution, not a real product.

Thoughts?

On Wed, 23 Oct 2013, security curmudgeon wrote:

: 
: re: Contexis
: 
: Are you guys sure this is software? Looks like a consulting / web design
: service, not a product.
: 
: http://www.exis-ti.com/es/index.html?locale=es
: 


More information about the VIM mailing list