Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  news  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date:  Fri, 12 Dec 2008 19:45:17 -0600
From:  Raphael Geissert <atomo64+debian@...il.com>
To: oss-security@...ts.openwall.com
Subject:  Re: CVE Request - roundcubemail

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

Jan Lieskovsky wrote:

> Hello Steve,
> 
>   this will need a new CVE identifier:
> http://trac.roundcube.net/ticket/1485618
> http://trac.roundcube.net/changeset/2148
> 

I became aware of some sort of code execution vulnerability one day before that
ticket was reported. After reviewing the file I determined that it isn't a
vulnerability in roundcube, but in PHP itself; but I'm open to be proved wrong.

Note that I have not yet determined how exactly the vulnerability is being
exploited, but am working on it.

Cheers,
- -- 
Raphael Geissert - Debian Maintainer
www.debian.org - get.debian.net

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAklDE64ACgkQYy49rUbZzlpO+QCfWpIGeSzor9+Su4bKGB640jq/
mp8AoJ/7u4opntkHMBIUt8KomFXSW9Ts
=gYTB
-----END PGP SIGNATURE-----

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux