Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <Pine.GSO.4.51.0807181148050.17955@faron.mitre.org>
Date: Fri, 18 Jul 2008 11:48:11 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: oss-security@...ts.openwall.com
cc: coley@...re.org
Subject: Re: CVE requests: joomla <1.5.4


======================================================
Name: CVE-2008-3225
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3225
Reference: MLIST:[oss-security] 20080712 CVE requests: joomla <1.5.4
Reference: URL:http://www.openwall.com/lists/oss-security/2008/07/12/2
Reference: CONFIRM:http://www.joomla.org/content/view/5180/1/

Joomla! before 1.5.4 allows attackers to access administration
functionality, which has unknown impact and attack vectors related to
a missing "LDAP security fix."


======================================================
Name: CVE-2008-3226
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3226
Reference: MLIST:[oss-security] 20080712 CVE requests: joomla <1.5.4
Reference: URL:http://www.openwall.com/lists/oss-security/2008/07/12/2
Reference: CONFIRM:http://www.joomla.org/content/view/5180/1/

The file caching implementation in Joomla! before 1.5.4 allows
attackers to access cached pages via unknown attack vectors.


======================================================
Name: CVE-2008-3227
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3227
Reference: MLIST:[oss-security] 20080712 CVE requests: joomla <1.5.4
Reference: URL:http://www.openwall.com/lists/oss-security/2008/07/12/2
Reference: CONFIRM:http://www.joomla.org/content/view/5180/1/

Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact
and attack vectors related to a "User Redirect Spam fix," possibly an
open redirect vulnerability.


======================================================
Name: CVE-2008-3228
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3228
Reference: MLIST:[oss-security] 20080712 CVE requests: joomla <1.5.4
Reference: URL:http://www.openwall.com/lists/oss-security/2008/07/12/2
Reference: CONFIRM:http://www.joomla.org/content/view/5180/1/
Reference: CONFIRM:http://www.joomla.org/content/view/5180/1/1/1/#htaccess

Joomla! before 1.5.4 does not configure .htaccess to apply certain
security checks that "block common exploits" to SEF URLs, which has
unknown impact and remote attack vectors.


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.