Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 07 Mar 2005 23:29:38 +0800
From:      Xin LI <delphij@frontfree.net>
To:        Kang Liu <liukang@bjut.edu.cn>
Cc:        delphij@freebsd.org
Subject:   Re: possible wrong date in 4a0b334d-8d8d-11d9-afa0-003048705d5a
Message-ID:  <1110209378.669.42.camel@spirit>
In-Reply-To: <310205489.09789@bjut.edu.cn>
References:  <310205489.09789@bjut.edu.cn>

next in thread | previous in thread | raw e-mail | index | archive | help

--=-0/dRYBxHvUV9XT2Vv7Vc
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

=E5=9C=A8 2005-03-07=E4=B8=80=E7=9A=84 22:41 +0800=EF=BC=8CKang Liu=E5=86=
=99=E9=81=93=EF=BC=9A
> Hi,
> 	The discovery date of 4a0b334d-8d8d-11d9-afa0-003048705d5a might be
> wrong. I've told delphij (the submitter of that entry), while he said tha=
t
> date came from the original source. But, as we all know, 2005 is not leap
> year, actually there is no Feb 29th 2005...I think it could be better if =
we
> change it to Feb 28th 2005.

Thanks for noticing this.  I'm aware of the issue, but it is the
official version claims Feb 29th:

	http://216.127.76.78/~neosecur/index.php?pagina=3Dadvisories&id=3D8

And my letter has been bounced before I have decided to commit it as-is.

I'm inclined in keeping it there until some of us can *actually* contact
the author to confirm the discovery date.  Replacing an official (while
it appears to be wrong) date with a guessed value (we will never know if
it is or is not wrong, and I personally infer it should be March 1st) is
more or less pointless.

BTW.  What's your opinion about the fix?  Without having a correct
filtering of user input, one can launch XSS attacks which poses users in
danger.

Cheers,
--=20
Xin LI <delphij delphij net>  http://www.delphij.net/

--=-0/dRYBxHvUV9XT2Vv7Vc
Content-Type: application/pgp-signature; name=signature.asc
Content-Description: 
	=?UTF-8?Q?=E8=BF=99=E6=98=AF=E4=BF=A1=E4=BB=B6=E7=9A=84=E6=95=B0?=
	=?UTF-8?Q?=E5=AD=97=E7=AD=BE=E5=90=8D=E9=83=A8?= =?UTF-8?Q?=E5=88=86?=

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (FreeBSD)

iD8DBQBCLHNi/cVsHxFZiIoRAoq+AJ47Jr1LioiHAAX4DLQjtlpj8ehc4QCfbpFO
O+4PgQwVIknMeeX7Hmwpbb8=
=dc2t
-----END PGP SIGNATURE-----

--=-0/dRYBxHvUV9XT2Vv7Vc--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?1110209378.669.42.camel>