Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  NEWS  community  lists  Wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Fri, 18 Jul 2008 11:48:11 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: oss-security@...ts.openwall.com
cc: coley@...re.org
Subject: Re: CVE requests: joomla <1.5.4


======================================================
Name: CVE-2008-3225
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3225
Reference: MLIST:[oss-security] 20080712 CVE requests: joomla <1.5.4
Reference: URL:http://www.openwall.com/lists/oss-security/2008/07/12/2
Reference: CONFIRM:http://www.joomla.org/content/view/5180/1/

Joomla! before 1.5.4 allows attackers to access administration
functionality, which has unknown impact and attack vectors related to
a missing "LDAP security fix."


======================================================
Name: CVE-2008-3226
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3226
Reference: MLIST:[oss-security] 20080712 CVE requests: joomla <1.5.4
Reference: URL:http://www.openwall.com/lists/oss-security/2008/07/12/2
Reference: CONFIRM:http://www.joomla.org/content/view/5180/1/

The file caching implementation in Joomla! before 1.5.4 allows
attackers to access cached pages via unknown attack vectors.


======================================================
Name: CVE-2008-3227
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3227
Reference: MLIST:[oss-security] 20080712 CVE requests: joomla <1.5.4
Reference: URL:http://www.openwall.com/lists/oss-security/2008/07/12/2
Reference: CONFIRM:http://www.joomla.org/content/view/5180/1/

Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact
and attack vectors related to a "User Redirect Spam fix," possibly an
open redirect vulnerability.


======================================================
Name: CVE-2008-3228
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3228
Reference: MLIST:[oss-security] 20080712 CVE requests: joomla <1.5.4
Reference: URL:http://www.openwall.com/lists/oss-security/2008/07/12/2
Reference: CONFIRM:http://www.joomla.org/content/view/5180/1/
Reference: CONFIRM:http://www.joomla.org/content/view/5180/1/1/1/#htaccess

Joomla! before 1.5.4 does not configure .htaccess to apply certain
security checks that "block common exploits" to SEF URLs, which has
unknown impact and remote attack vectors.


Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ