|
|||||||||||
|
Re: [SECURITY] [DSA 1430-1] New libnss-ldap packages fix denial of service
From: Dominic Hargreaves <dom(at)earth.li>
Date: Tue Dec 11 2007 - 18:03:05 EST
> Package : libnss-ldap I believe this vulnerability has been mislablled as a denial of service vulnerability, rather than an information disclosure vulnerability: According to various sources, eg http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5794 https://bugzilla.redhat.com/show_bug.cgi?id=154314 This bug may allow users to obtain effective credentials of a different user (under certain confurations). It may be worth reissuing the advisory to make this clear. Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Tue Dec 11 18:57:25 2007 This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:54:24 EDT |
||||||||||
|
|||||||||||