Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20110620194911.GM11550@foo.fgeek.fi>
Date: Mon, 20 Jun 2011 22:49:11 +0300
From: Henri Salo <henri@...v.fi>
To: oss-security@...ts.openwall.com
Cc: bressers@...hat.com, incidents@...rt.org
Subject: CVE request: Joomla unspecified information disclosure
 vulnerability

Couldn't find a CVE-identifier for this issue. Joomla does have too many vulnerabilities. Joomla prior to 1.5.23 contains a flaw that may lead to an unauthorized information disclosure. Should this one get a 2010 or 2011 identifier?

Reported: 2010-12-08
Joomla advisory: 2011-04-01
Release with a fix (version 1.5.23): 2011-04-04

References:
http://developer.joomla.org/security/news/9-security/10-core-security/340-20110401-core-information-disclosure.html
http://www.joomla.org/announcements/release-news/5367-joomla-1523-released.html
http://osvdb.org/show/osvdb/71587
http://secunia.com/advisories/44028/

I hope this request isn't duplicate. I included oCERT to this email as Joomla is part of that group. Please notify me and mailing-list if this issue already has a CVE-identifier.

Best regards,
Henri Salo

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.