|
Message-ID: <50B337DE.6050104@moritz-naumann.com> Date: Mon, 26 Nov 2012 10:35:26 +0100 From: Moritz Naumann <oss-security@...itz-naumann.com> To: oss-security@...ts.openwall.com Subject: Re: Security issue in icecast -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Hi, I'm not sure it's worth spending your time on this, so please decide for yourselves: 1. Spelling issue in CVE-2011-4612: > On 12/15/2011 11:25 AM, Jamie Strandboge wrote: >> A security bug was reported by Moritz Naumann against icecast in >> Ubuntu. > Details from the public bug follow: > https://launchpad.net/bugs/894782 > >> From the reporter: "Newline injection in error.log [..] The CVE overview now reads: > icecast before 2.3.3 allows remote attackers to inject control > characters such as newlines into the error loc (error.log) via a > crafted URL. I would think "error loc" should actually say "error log". 2. Access complexity "Low" is correct since specialized access conditions or extenuating circumstances do not exist and the first three examples provided at http://www.first.org/cvss/cvss-guide.html#i2.1.2 do apply. Thanks, Moritz Naumann -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iQIcBAEBCgAGBQJQszfAAAoJEL2W7K2TRQCwJ6oP/RjTNXSF4H65cDEp3b6Z/y8E CbF165PSI4j6kqoqtYxY+V9Eu8r7x7czuCjqZTC+DzKxfOi2lb+uWUJ01a5Ldnu1 UX1z210+HOf+XMwDqp3BnaWJwK71ZCIH+9eRkS/6nAWVe04Pk3x5n90fvSJjDvt/ AAbcAtZiiy9Ef81MtK97amHy4GQqR7I1yMQ9BqBV4PB3vGWKp/pIR+bVg3NHbaHp N4fD9EdKh/LDJDd24Bv9ZKnhp/fumJLwsqkGsJ8ePnqitUxcUZjXUqVTGdhXOmvW SraEjudIr8Cst6+ykFDkMZYsGe4edhG4MsFFZkmtLvoOsOd4SyuR7jmD58jBSwQj 1fvVaXICmM7mUCeDbdMeJldGzXGoCoEFwBhdBVMvUm4/572CsWzEug9f0QlhqKl4 O1tGG9RuMyD0+5kJ7y1Ay8WdLupPHlUhU+ijFusBIj15+AKa56UCktN41xpvLzUf c5DO0SBfA9AWcv2+8mxDS752pQ92Cldd6GM3BXtUvmVAeYmn0hDZGev2r1fYCNbl RrnoOcj0ViSscOd1GsX2vd9u+CE7yvmwu+b7KGuWM6htPCygbT1ntga7YGPZN2P2 utLgPJ6+mwEgJwHzxNECCecfxXOAbWD0mvvXBZIEXxfkY9XV+3ZH2S1/qMH5UBn4 HXYH+XhCcgxI+X42QfDM =D0i4 -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.