Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Advisory description text

From: Moritz Muehlenhoff <jmm(at)inutil.org>
Date: Tue Jan 08 2008 - 13:35:17 EST


Adam Majer wrote:

> Moritz Muehlenhoff wrote:
>> CVE-2007-3382
>>
>> It was discovered that single quotes (') in cookies were treated
>> as a delimiter, which could lead to an information leak.
>>
>> CVE-2007-3385
>>
>> It was discovered that the character sequence \" in cookies was
>> handled incorrectly, which could lead to an information leak.
>>
>> CVE-2007-5461
>>
>> It was discovered that the WebDAV servlet is vulnerable to absolute
>> path traversal.
>>
>
> First of all, this is not targeted at this specific advisory or any
> person writing this advisory. :)
>
> Generally, the first little bits of each and every CVE description
> above, as well as in other advisories sent out by Debian, is not needed.
> Please, remove the "It was discovered that" part from any templates that
> you may be using. That part is not needed. It is also implied and
> doesn't add anything to the advisory.

This is for consistency. Normally, we credit the person, who discovered the issues, like:

CVE-2008-0100

       Adam Majer discovered a stylistic error in advisory texts, which
       may lead to local admin boredom, resulting in denial of service.

Only if the researcher is unknown it's simply replaced by "It was discovered".

Cheers,

        Moritz

-- 
To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Received on Tue Jan 8 13:36:40 2008

This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:55:08 EDT

Do you need help?X

Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library