[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 13 Oct 2009 15:26:25 +0200
From: Jan Lieskovsky <jlieskov@...hat.com>
To: oss-security <oss-security@...ts.openwall.com>
CC: "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: Duplicate CVE assignment notification [was: CVE
id request: django]
Hello Steve, vendors,
two CVE ids have been assigned for this issue:
CVE-2009-3695 and CVE-2009-3610.
Will take CVE-2009-3695 as the proper one, as it has description already.
CVE-2009-3610 should be rejected.
Thanks && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team
Josh Bressers wrote:
> Please use CVE-2009-3610
>
> Thanks.
>
> ----- "Raphael Geissert" <geissert@...ian.org> wrote:
>
>> -----BEGIN PGP SIGNED MESSAGE-----
>> Hash: SHA1
>>
>> Hi,
>>
>> A vulnerability has been found in Django's forms library that can be
>> used to
>> perform DoS attacks via certain email addresses or URLs that make the
>> validation regular expressions consume CPU resources.
>>
>> The vulnerability is said to be being exploited on live
>> installations.
>>
>> References:
>> http://www.djangoproject.com/weblog/2009/oct/09/security/
>> http://groups.google.com/group/django-users/browse_thread/thread/15df9e45118dfc51/677e54bd6c6e283b
>> http://lists.debian.org/debian-security-announce/2009/msg00227.html
>>
>> Please assign a CVE identifier.
>>
>> Kind regards,
>> - --
>> Raphael Geissert - Debian Developer
>> www.debian.org - get.debian.net
>>
>> -----BEGIN PGP SIGNATURE-----
>> Version: GnuPG v1.4.10 (GNU/Linux)
>>
>> iEYEARECAAYFAkrREJQACgkQYy49rUbZzlpwswCgjSOAiDSfYGYiE+ZjE9i6+Zmf
>> 3MkAoJN9qvxGAzfzsgiFW8XAuP1wan81
>> =nsNz
>> -----END PGP SIGNATURE-----
>
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ