Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 12 May 2012 11:27:50 -0400
From: micah anderson <micah@...eup.net>
To: Kurt Seifried <kseifried@...hat.com>, oss-security@...ts.openwall.com
Subject: Re: CVE request: sympa (try again)

On Fri, 11 May 2012 23:58:33 -0600, Kurt Seifried <kseifried@...hat.com> wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> On 05/11/2012 12:03 PM, micah wrote:
> > 
> > Hi,
> > 
> > Please assign a CVE for Sympa, any version prior to 6.1.11. It is 
> > possible to open the archive management ("arc_manage") page for
> > any list, even those set to only be available to members, giving
> > anyone the option to download the archive, or delete the archive.
> > 
> > http://www.sympa.org/distribution/latest-stable/NEWS 
> > https://sourcesup.renater.fr/scm/viewvc.php/branches/sympa-6.0-branch/wwsympa/wwsympa.fcgi.in?root=sympa&r1=6706&r2=7358&pathrev=7358
> >
> >  thank you, micah
> > 
> > ps - for some reason the previous message is formatted strange, so
> > I'm sending this one without the signature
> > 
> 
> Ok I see this one and several more:
> 
> ================================
> 
> 6.1.11		May 11, 2012
> Bug fixes:
> [7358] wwsympa/wwsympa.fcgi.in:  Fixing a potential security issue
> related to archives
> 
> Can you confirm these and I will assign CVE's for the outstanding issues.

I am only able to confirm the above issue, I am not a sympa developer I
just was involved in the above issue. 

What sort of 'confirmation' are you looking for? It seems like the
changelog entries are pretty good confirmation. Perhaps you are looking
for more details of the issues, those you could obtain from the sympa
list.

micah

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.