Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4F50FD4A.5030003@redhat.com>
Date: Fri, 02 Mar 2012 10:03:06 -0700
From: Kurt Seifried <kseifried@...hat.com>
To: oss-security@...ts.openwall.com
CC: Henri Salo <henri@...v.fi>
Subject: Re: CVE-request: Joomla core information disclosure
 1.7.1

On 03/01/2012 11:58 PM, Henri Salo wrote:
> On Thu, Mar 01, 2012 at 10:14:40PM -0700, Kurt Seifried wrote:
>> On 03/01/2012 02:07 PM, Henri Salo wrote:
>>> Hello,
>>>
>>> It seems that this issue does not yet have CVE-identifier.
>>>
>>> http://developer.joomla.org/security/news/371-20111002-core-information-disclosure.html
>>>
>>> I can't never be sure with Joomla so maybe someone wants to verify this before assigment.
>>>
>>> - Henri Salo
>>
>> Looks like you asked for one for 20111001
>> (http://seclists.org/oss-sec/2011/q4/89) but I can't find a request for
>> 20111002 anywhere.
>>
>> For Joomla! core information disclosure 20111002 please use CVE-2011-4937.
>>
>> -- 
>> Kurt Seifried Red Hat Security Response Team (SRT)
> 
> http://seclists.org/oss-sec/2012/q1/524 so the CVE seems to be CVE-2011-3629. Sorry again for the hassle. I think CVE-2011-4937 is now duplicate. How do we get Joomla's security personnel to request CVE-identifiers by themselves and add them to advisories? They do belong to oCERT.
> 
> - Henri Salo
> ps. SORRY :)

Huh?

http://developer.joomla.org/security/news/371-20111002-core-information-disclosure.html

and

http://developer.joomla.org/security/news/371-20111002-core-information-disclosure.html

are entirely different issues (one is "Weak encryption causes potential
information disclosure" the other is "Inadequate error checking causes
potential information disclosure."), so two issues, two CVE's. We split
based on (among other things) the underlying issues, not the outcome.

These two CVE's are fine.

-- 
Kurt Seifried Red Hat Security Response Team (SRT)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.