RE: ban the use and implementation of UTF-7

At 01:21 PM 2006-12-22, Paul Cotton wrote:
> > But as far as the browsers are concerned, if the TAG can come
> > up with a finding that e.g. also gives some more details and
> > examples about the security issues you mention, then we might
> > also be able to point to this document from anything on the
> > IETF or IANA side.
>
>Here is a publicly available description of this problem:
>http://archives.neohapsis.com/archives/fulldisclosure/2006-10/0296.html
>
>/paulc

Also see
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5442

And see below for other CVE entries with UTF-7
http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=UTF-7

Paul 

Received on Wednesday, 3 January 2007 18:28:11 UTC