oss-sec mailing list archives

Re: CVE request: phpbb 3.0.7 and before 3.0.5


From: "Steven M. Christey" <coley () linus mitre org>
Date: Wed, 19 May 2010 18:59:42 -0400 (EDT)


On Wed, 19 May 2010, Josh Bressers wrote:

----- "Hanno Böck" <hanno () hboeck de> wrote:
Am Dienstag 18 Mai 2010 schrieb Josh Bressers:

    http://www.phpbb.com/community/viewtopic.php?f=14&p=9764445
    # [Sec] Only use forum id supplied for posting if global
    announcement detected. (Reported by nickvergessen)

CVE-2010-1630 phpbb 3.0.5 unspecified flaw

Shouldn't this be CVE-2009-XXXX ?

Ideally yes, but the ID is out there so we may as well use it. This happens sometimes. It doesn't look like it became "widely public" until a couple months ago, so a 2010 ID isn't too bad.

- Steve

Current thread: