oss-sec mailing list archives
Re: CVE request: drupal issue in < 5.9
From: Nico Golde <oss-security+ml () ngolde de>
Date: Sun, 27 Jul 2008 13:19:16 +0200
Hi, * Steven M. Christey <coley () linus mitre org> [2008-07-27 11:41]:
On Sat, 26 Jul 2008, Miklos Vajna wrote:On Sat, Jul 26, 2008 at 09:27:33PM +0200, Nico Golde <oss-security+ml () ngolde de> wrote:This is CVE-2008-3222.Isn't this different? It refers to http://www.openwall.com/lists/oss-security/2008/07/10/3 which is a bug fixed in 5.8. The issue I'm talking about is _not_ fixed in 5.8.My interpretation of this new advisory is that they meant to fix the session fixation in 5.8, but they didn't. The original advisory covered multiple other issues as well. So this new advisory might better be considered a clarification of versions for the session fixation, rather than a regression error or incomplete fix (which would require a new CVE). Granted, the lack of specifics from Drupal makes it difficult to be certain about what happened.
Yes, I have no idea either but at least the patch stayed the same. Cheers Nico -- Nico Golde - http://www.ngolde.de - nion () jabber ccc de - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted.
Attachment:
_bin
Description:
Current thread:
- CVE request: drupal issue in < 5.9 Miklos Vajna (Jul 26)
- Re: CVE request: drupal issue in < 5.9 Nico Golde (Jul 26)
- Re: CVE request: drupal issue in < 5.9 Miklos Vajna (Jul 26)
- Re: CVE request: drupal issue in < 5.9 Steven M. Christey (Jul 26)
- Re: CVE request: drupal issue in < 5.9 Nico Golde (Jul 27)
- Re: CVE request: drupal issue in < 5.9 Miklos Vajna (Jul 27)
- Re: CVE request: drupal issue in < 5.9 Nico Golde (Jul 27)
- Re: CVE request: drupal issue in < 5.9 Miklos Vajna (Jul 27)
- Re: CVE request: drupal issue in < 5.9 Miklos Vajna (Jul 26)
- Re: CVE request: drupal issue in < 5.9 Nico Golde (Jul 26)