Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  news  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Tue, 8 Jul 2008 13:38:04 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: oss-security@...ts.openwall.com
cc: coley@...re.org
Subject: Re: CVE request: simple machines forum


On Sun, 6 Jul 2008, Hanno [utf-8] Böck wrote:

> http://www.simplemachines.org/community/index.php?P=c3696c2022b54fa50c5f341bf5710aa3&topic=236816.0
>
>
> "This version addresses a few security issues and fixes some small bugs."
>
> These sound like security issues:
> * Sanitation of $topic wasn't always done right.

This might be a straightforward bug - maybe the topic is always
"sanitized" to 0 and prevents legitimate display of pages.

> * Fixed a vulnerability with the use of the html-tag - issue reported by
> Jessica Hope.

Use CVE-2008-3073, see below.

There's also this:

  Improved the random generator seeding for PHP < 4.2.0 - issue reported
  by Jessica Hope

Since Jessica has a track record for reporting SMF vulns, I think there's
a high probability that this issue is also security-related.

So, use CVE-2008-3072 for this.

> Though they don't list which issues are security relevant.

They also fixed CVE-2008-2019: "Increased the randomness of the Captcha
sound."  This, in conjunction with the original researcher's claim of
vendor notification, seems like sufficient acknowledgement.

> They also don't mention if CVE-2007-5943 is fixed.

... also CVE-2008-0284, CVE-2008-0775, and others.

- Steve

======================================================
Name: CVE-2008-3072
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3072
Reference: CONFIRM:http://www.simplemachines.org/community/index.php?P=c3696c2022b54fa50c5f341bf5710aa3&topic=236816.0

Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before
1.0.13, when running in PHP before 4.2.0, does not properly seed the
random number generator, which has unknown impact and attack vectors.


======================================================
Name: CVE-2008-3073
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3073
Reference: CONFIRM:http://www.simplemachines.org/community/index.php?P=c3696c2022b54fa50c5f341bf5710aa3&topic=236816.0

Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.x before
1.1.5 and 1.0.x before 1.0.13 has unknown impact and attack vectors,
probably cross-site scripting (XSS), related to "use of the html-tag."


Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux