[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] CVE Request for Horde and Squirrelmail
From:       "Steven M. Christey" <coley () linus ! mitre ! org>
Date:       2010-05-25 21:12:07
Message-ID: Pine.GSO.4.64.1005251706220.27983 () faron ! mitre ! org
[Download RAW message or body]


While these port-scanning types of issues are rarely reported, there is 
precedents for them, especially in the web application security world (see 
Jeremiah Grossman's work on port-scanning through web browsers, for a 
start).

Even though the consequences may be minimal, they still allow an attacker 
from *outside* a network to determine the state of machines that live 
*inside* that network, even when the attacker does not have direct access 
to the internal netork.  So there is an information leak.

As such, the CVE assignment is appropriate.  (To the Horde devs, if you 
wish to publish a dispute within the CVE description itself, contact me 
offline; the description can at least be written to emphasize that it only 
happens when sysadmins don't follow documentation.)

- Steve
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic