Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Mon, 26 Nov 2012 10:35:26 +0100
From: Moritz Naumann <oss-security@...itz-naumann.com>
To: oss-security@...ts.openwall.com
Subject: Re: Security issue in icecast

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi,

I'm not sure it's worth spending your time on this, so please decide
for yourselves:

1. Spelling issue in CVE-2011-4612:

> On 12/15/2011 11:25 AM, Jamie Strandboge wrote:
>> A security bug was reported by Moritz Naumann against icecast in
>>  Ubuntu.

> Details from the public bug follow: 
> https://launchpad.net/bugs/894782
> 
>> From the reporter: "Newline injection in error.log
[..]

The CVE overview now reads:
> icecast before 2.3.3 allows remote attackers to inject control 
> characters such as newlines into the error loc (error.log) via a 
> crafted URL.

I would think "error loc" should actually say "error log".


2. Access complexity

"Low" is correct since specialized access conditions or extenuating
circumstances do not exist and the first three examples provided at
  http://www.first.org/cvss/cvss-guide.html#i2.1.2
do apply.

Thanks,

Moritz Naumann
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAEBCgAGBQJQszfAAAoJEL2W7K2TRQCwJ6oP/RjTNXSF4H65cDEp3b6Z/y8E
CbF165PSI4j6kqoqtYxY+V9Eu8r7x7czuCjqZTC+DzKxfOi2lb+uWUJ01a5Ldnu1
UX1z210+HOf+XMwDqp3BnaWJwK71ZCIH+9eRkS/6nAWVe04Pk3x5n90fvSJjDvt/
AAbcAtZiiy9Ef81MtK97amHy4GQqR7I1yMQ9BqBV4PB3vGWKp/pIR+bVg3NHbaHp
N4fD9EdKh/LDJDd24Bv9ZKnhp/fumJLwsqkGsJ8ePnqitUxcUZjXUqVTGdhXOmvW
SraEjudIr8Cst6+ykFDkMZYsGe4edhG4MsFFZkmtLvoOsOd4SyuR7jmD58jBSwQj
1fvVaXICmM7mUCeDbdMeJldGzXGoCoEFwBhdBVMvUm4/572CsWzEug9f0QlhqKl4
O1tGG9RuMyD0+5kJ7y1Ay8WdLupPHlUhU+ijFusBIj15+AKa56UCktN41xpvLzUf
c5DO0SBfA9AWcv2+8mxDS752pQ92Cldd6GM3BXtUvmVAeYmn0hDZGev2r1fYCNbl
RrnoOcj0ViSscOd1GsX2vd9u+CE7yvmwu+b7KGuWM6htPCygbT1ntga7YGPZN2P2
utLgPJ6+mwEgJwHzxNECCecfxXOAbWD0mvvXBZIEXxfkY9XV+3ZH2S1/qMH5UBn4
HXYH+XhCcgxI+X42QfDM
=D0i4
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.