oss-sec mailing list archives
Re: CVE-2008-4619 / milw0rm6775
From: Tomas Hoger <thoger () redhat com>
Date: Mon, 3 Nov 2008 09:02:21 +0100
Hi Steven! On Fri, 31 Oct 2008 16:18:36 -0400 (EDT) "Steven M. Christey" <coley () linus mitre org> wrote:
Looks like this is a dupe of CVE-2007-0165 after all... http://www.securityfocus.com/bid/21964/ http://secunia.com/advisories/23700/ http://secunia.com/advisories/32403/Nothing against these sources but in general CVE wants a solid "logic chain" between 2 descriptions before declaring a dupe. In this case CVE-2007-0165 is anchored on a very vague description from Sun about something in libnsl. CVE-2008-4619 is quite specific. Just because it's the same rpcbind service is insufficient as we all know that the same package can contain multiple security bugs.
Sorry for not choosing word properly here. I probably should have used "looks like this *may* be a dupe of...". My reasoning for calling it dupe was that CVE-2007-0165 links BID-21964, which has the same exploit attached as is available on milw0rm as 6775. It's not clear when exploit code was added to the BID, though. -- Tomas Hoger / Red Hat Security Response Team
Current thread:
- CVE-2008-4619 / milw0rm6775 Tomas Hoger (Oct 28)
- Re: CVE-2008-4619 / milw0rm6775 Tomas Hoger (Oct 29)
- Re: CVE-2008-4619 / milw0rm6775 Steven M. Christey (Oct 31)
- Re: CVE-2008-4619 / milw0rm6775 Tomas Hoger (Nov 02)
- Re: CVE-2008-4619 / milw0rm6775 Steven M. Christey (Oct 31)
- Re: CVE-2008-4619 / milw0rm6775 Tomas Hoger (Oct 29)