oss-sec mailing list archives

Re: Re: CVE Request (PHP)


From: Robert Buchholz <rbu () gentoo org>
Date: Tue, 6 May 2008 18:46:05 +0200

On Friday 02 May 2008, Steven M. Christey wrote:
* Properly address incomplete multibyte chars inside
escapeshellcmd() identified by Stefan Esser.

Use CVE-2008-2051

Stefan Esser released a detailed advisory on this issue:
http://www.sektioneins.de/advisories/SE-2008-03.txt

Also, we could need a CVE for the "GENERATE_SEED() Weak Random Number 
Seed Vulnerability": 
http://www.sektioneins.de/advisories/SE-2008-02.txt

Robert

Attachment: signature.asc
Description: This is a digitally signed message part.


Current thread: