Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 13 Oct 2009 15:26:25 +0200
From: Jan Lieskovsky <jlieskov@...hat.com>
To: oss-security <oss-security@...ts.openwall.com>
CC: "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: Duplicate CVE assignment notification [was: CVE
 id request: django]

Hello Steve, vendors,

   two CVE ids have been assigned for this issue:

CVE-2009-3695 and CVE-2009-3610.

Will take CVE-2009-3695 as the proper one, as it has description already.
CVE-2009-3610 should be rejected.

Thanks && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team

Josh Bressers wrote:
> Please use CVE-2009-3610
> 
> Thanks.
> 
> ----- "Raphael Geissert" <geissert@...ian.org> wrote:
> 
>> -----BEGIN PGP SIGNED MESSAGE-----
>> Hash: SHA1
>>
>> Hi,
>>
>> A vulnerability has been found in Django's forms library that can be
>> used to
>> perform DoS attacks via certain email addresses or URLs that make the
>> validation regular expressions consume CPU resources.
>>
>> The vulnerability is said to be being exploited on live
>> installations.
>>
>> References:
>> http://www.djangoproject.com/weblog/2009/oct/09/security/
>> http://groups.google.com/group/django-users/browse_thread/thread/15df9e45118dfc51/677e54bd6c6e283b
>> http://lists.debian.org/debian-security-announce/2009/msg00227.html
>>
>> Please assign a CVE identifier.
>>
>> Kind regards,
>> - -- 
>> Raphael Geissert - Debian Developer
>> www.debian.org - get.debian.net
>>
>> -----BEGIN PGP SIGNATURE-----
>> Version: GnuPG v1.4.10 (GNU/Linux)
>>
>> iEYEARECAAYFAkrREJQACgkQYy49rUbZzlpwswCgjSOAiDSfYGYiE+ZjE9i6+Zmf
>> 3MkAoJN9qvxGAzfzsgiFW8XAuP1wan81
>> =nsNz
>> -----END PGP SIGNATURE-----
> 

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ