Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 26 Jul 2008 21:55:07 +0200
From: Miklos Vajna <vmiklos@...galware.org>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: drupal issue in < 5.9

On Sat, Jul 26, 2008 at 09:27:33PM +0200, Nico Golde <oss-security+ml@...lde.de> wrote:
> Hi Miklos,
> * Miklos Vajna <vmiklos@...galware.org> [2008-07-26 21:13]:
> > DRUPAL SA-2008-046
> > http://drupal.org/node/286417
> > 
> > Contains a session fixation.
> 
> This is CVE-2008-3222.

Isn't this different?

It refers to http://www.openwall.com/lists/oss-security/2008/07/10/3
which is a bug fixed in 5.8.

The issue I'm talking about is _not_ fixed in 5.8.

Thanks.

Content of type "application/pgp-signature" skipped

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.