The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


Fedora, Ubuntu publish wrong advisories for CVE-2007-6318


<< Previous INDEX Search src / Print Next >>
Date: Sat, 22 Mar 2008 07:46:06 +0800
From: Abel Cheung <abelcheung@gmail.com.>
To: bugtraq@securityfocus.com
Subject: Fedora, Ubuntu publish wrong advisories for CVE-2007-6318
Message-ID: <20080321234605.GA17484@deaddog.org.>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
        protocol="application/pgp-signature"; boundary="VS++wcV0S1rZb1Fb"
Content-Disposition: inline
X-Virus-Scanned: antivirus-gw at tyumen.ru


--VS++wcV0S1rZb1Fb
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

I have just found some false changelogs and advisories published
about a WordPress vuln I published a while ago.

Fedora:
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg000=
79.html

Ubuntu:
https://bugs.launchpad.net/debian/+source/wordpress/+bug/181416

What they have fixed is another vuln published by Michael Brooks,
about an access control failure in WordPress, instead of SQL injection.
The detail of concerned vuln is available at

http://xforce.iss.net/xforce/xfdb/39409

CVE-2007-6318 is NOT fixed as of version 2.3.3.


Abel

--=20
Abel Cheung   (GPG Key: 0xC67186FF)
Key fingerprint: 671C C7AE EFB5 110C D6D1  41EE 4152 E1F1 C671 86FF
--------------------------------------------------------------------
* My blog - http://me.abelcheung.org/
* Opensource Application Knowledge Assoc. - http://oaka.org/

--VS++wcV0S1rZb1Fb
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFH5Ei9QVLh8cZxhv8RAr4TAJ9/0co59SZyFB6qQ0DtnExnl6tOkwCeL39E
7Z0HA6dLChpJ/2q9aE2uXaY=
=Ve7v
-----END PGP SIGNATURE-----

--VS++wcV0S1rZb1Fb--


<< Previous INDEX Search src / Print Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2024 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру