oss-sec mailing list archives

Re: CVE request: drupal issue in < 5.9


From: "Steven M. Christey" <coley () linus mitre org>
Date: Sat, 26 Jul 2008 16:44:16 -0400 (EDT)


On Sat, 26 Jul 2008, Miklos Vajna wrote:

On Sat, Jul 26, 2008 at 09:27:33PM +0200, Nico Golde <oss-security+ml () ngolde de> wrote:

This is CVE-2008-3222.

Isn't this different?

It refers to http://www.openwall.com/lists/oss-security/2008/07/10/3
which is a bug fixed in 5.8.

The issue I'm talking about is _not_ fixed in 5.8.

My interpretation of this new advisory is that they meant to fix the
session fixation in 5.8, but they didn't.  The original advisory covered
multiple other issues as well.  So this new advisory might better be
considered a clarification of versions for the session fixation, rather
than a regression error or incomplete fix (which would require a new CVE).

Granted, the lack of specifics from Drupal makes it difficult to be
certain about what happened.

- Steve


Current thread: