Home page logo
/

oss-sec logo oss-sec mailing list archives

Re: Strange CVE situation (at least one ID should come of this)
From: Vincent Danen <vdanen () redhat com>
Date: Wed, 5 Dec 2012 17:58:59 -0700

* [2012-12-03 22:26:29 -0700] Kurt Seifried wrote:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 10/26/2012 01:54 PM, Josh Bressers wrote:
Hello,

This Squirrelmail plugin came to my attention a few weeks back:
http://squirrelmail.org/plugin_view.php?id=117

It's from 2004, which is suspect in itself, but I took a look after
someone asked. It's pretty scary in there.

If I was to list the security problems I found after a few minutes
of looking, they are:

* It uses MD5 passwords

Going with this one since there's a good number of MD5 related CVE's
already.

Please use CVE-2012-5623 for this issue.

Shouldn't this be a 2004 CVE, since it was fixed in 2004?

--
Vincent Danen / Red Hat Security Response Team

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault