Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in all versions #278

Open
AzraelsBlade opened this issue Nov 25, 2024 · 5 comments
Open

Vulnerability in all versions #278

AzraelsBlade opened this issue Nov 25, 2024 · 5 comments

Comments

@AzraelsBlade
Copy link

Good morning,

Recently I discovered a vulnerability affecting all versions of phpLDAPadmin, please @leenooks reach me out so I can give you all the details.

Thank you and kind regards

@williamdes
Copy link

Reading #274 you should be the one initiating the contact

@diraneyya
Copy link

Seems suspicious indeed. Looks like someone have found an interesting phishing tactic.

@AzraelsBlade
Copy link
Author

Hi again.

As @williamdes said, I have contacted @leenooks by mail and explained all the details about the vulnerability (no reply so far).
If I do not get a response in the next few months, maybe I can email you @williamdes so you can prepare a security release for Debian.

Thanks to all of you!

(PD: @diraneyya I have better things to do than scam people on the Internet hahaha)

@diraneyya
Copy link

Hi again.

As @williamdes said, I have contacted @leenooks by mail and explained all the details about the vulnerability (no reply so far). If I do not get a response in the next few months, maybe I can email you @williamdes so you can prepare a security release for Debian.

Thanks to all of you!

(PD: @diraneyya I have better things to do than scam people on the Internet hahaha)

I truly hope so! All the power to you if you have actually found a vulnerability and help fix it. I will make sure to donate to your crypto wallet when this happens.

@williamdes
Copy link

maybe I can email you @williamdes so you can prepare a security release for Debian.

Please file a CVE from the MITRE online form or email and also send me the patch to distribute
I think this is the best way forward:

  • advise to the world with a CVE
  • distribute a patch

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants