Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Mon, 5 May 2008 12:51:28 -0400 (EDT)
From: "Steven M. Christey" <>
Subject: Re: asterisk dupe?

On Wed, 30 Apr 2008, Moritz Muehlenhoff wrote:

> I think there's been a dupe in a recent CVE assignment for
> asterisk. CVE-2008-1923 appears to be a duplicate of
> CVE-2007-4103.

These are most likely different based on different advisories from
Asterisk, as well as different types of issue - CVE-2007-4103 is basically
resource exhaustion via "malformed" handshakes, and CVE-2008-1923 involves
Smurf-ish traffic amplification being sent to a spoofed address.

- Steve

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.