Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 26 Jan 2012 03:50:14 +0200
From: Henri Salo <henri@...v.fi>
To: Kurt Seifried <kseifried@...hat.com>
Cc: oss-security@...ts.openwall.com
Subject: Re: Fwd Joomla! Security News 2012-01

On Wed, Jan 25, 2012 at 05:07:27PM -0700, Kurt Seifried wrote:
> On 01/25/2012 07:17 AM, Henri Salo wrote:
> > Does someone know if these already have CVE-identifiers? Joomla just released this advisory.
> > 
> > - Henri Salo
> > 
> > ----- Forwarded message from Joomla! Developer Network - Security News <no_reply@...mla.org> -----
> > 
> > Date: Wed, 25 Jan 2012 13:21:21 +0000
> > From: Joomla! Developer Network - Security News <no_reply@...mla.org>
> > To: henri@...v.fi
> > Subject: Joomla! Security News
> > 
> > Joomla! Developer Network - Security News
> 
> Are these the correct URL's/descriptions (see below)?
<snip>

To me that looks OK, but I just asked IF there is already CVEs assigned to these security vulnerabilities or not. I don't know if Joomla has requested identifiers from MITRE or done it via oCERT for example. Advisories, which are at the moment just oneliners in their webpage do not at least list any CVE-identifiers.

- Henri Salo

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.