Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 13 Oct 2009 15:26:25 +0200
From: Jan Lieskovsky <jlieskov@...hat.com>
To: oss-security <oss-security@...ts.openwall.com>
CC: "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: Duplicate CVE assignment notification [was: CVE
 id request: django]

Hello Steve, vendors,

   two CVE ids have been assigned for this issue:

CVE-2009-3695 and CVE-2009-3610.

Will take CVE-2009-3695 as the proper one, as it has description already.
CVE-2009-3610 should be rejected.

Thanks && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team

Josh Bressers wrote:
> Please use CVE-2009-3610
> 
> Thanks.
> 
> ----- "Raphael Geissert" <geissert@...ian.org> wrote:
> 
>> -----BEGIN PGP SIGNED MESSAGE-----
>> Hash: SHA1
>>
>> Hi,
>>
>> A vulnerability has been found in Django's forms library that can be
>> used to
>> perform DoS attacks via certain email addresses or URLs that make the
>> validation regular expressions consume CPU resources.
>>
>> The vulnerability is said to be being exploited on live
>> installations.
>>
>> References:
>> http://www.djangoproject.com/weblog/2009/oct/09/security/
>> http://groups.google.com/group/django-users/browse_thread/thread/15df9e45118dfc51/677e54bd6c6e283b
>> http://lists.debian.org/debian-security-announce/2009/msg00227.html
>>
>> Please assign a CVE identifier.
>>
>> Kind regards,
>> - -- 
>> Raphael Geissert - Debian Developer
>> www.debian.org - get.debian.net
>>
>> -----BEGIN PGP SIGNATURE-----
>> Version: GnuPG v1.4.10 (GNU/Linux)
>>
>> iEYEARECAAYFAkrREJQACgkQYy49rUbZzlpwswCgjSOAiDSfYGYiE+ZjE9i6+Zmf
>> 3MkAoJN9qvxGAzfzsgiFW8XAuP1wan81
>> =nsNz
>> -----END PGP SIGNATURE-----
> 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.