oss-sec mailing list archives
Re: Thoughts on a vuln/CVE?
From: Russ Allbery <rra () stanford edu>
Date: Mon, 17 Jun 2013 23:19:27 -0700
Kurt Seifried <kseifried () redhat com> writes:
We have software with a now insecure configuration as it points to a site that may or may not be under attacker control. It seems to me like this might be a candidate for a CVE. Thoughts and comments for and against are welcome (I'm on the fence myself).
It's possibly worth noting that the repository that was at that site was signed and had been for some years, and the key was not compromised. So not only would the site need to be taken over by an attacker for a successful exploit, but the affected user would have to ignore the copius warnings that APT produces when installing packages from an untrusted archive, or have configured APT to not check repository signatures. -- Russ Allbery (rra () stanford edu) <http://www.eyrie.org/~eagle/>
Current thread:
- Thoughts on a vuln/CVE? Kurt Seifried (Jun 17)
- Re: Thoughts on a vuln/CVE? Yves-Alexis Perez (Jun 17)
- Re: Thoughts on a vuln/CVE? Russ Allbery (Jun 17)
- Re: Thoughts on a vuln/CVE? Moritz Muehlenhoff (Jun 17)
- Re: Thoughts on a vuln/CVE? Kurt Seifried (Jun 17)
- Re: Thoughts on a vuln/CVE? Florian Weimer (Jun 18)
- Re: Thoughts on a vuln/CVE? Simon McVittie (Jun 18)
- Re: Thoughts on a vuln/CVE? Dave Walker (Jun 18)
- Re: Thoughts on a vuln/CVE? Tim (Jun 18)
- Re: Thoughts on a vuln/CVE? Moritz Muehlenhoff (Jun 18)
- Re: Thoughts on a vuln/CVE? Kurt Seifried (Jun 18)
- Re: Thoughts on a vuln/CVE? Florian Weimer (Jun 18)
- Re: Thoughts on a vuln/CVE? Kurt Seifried (Jun 18)
- Re: Thoughts on a vuln/CVE? Kurt Seifried (Jun 17)