Bug#335662: phpbb2: Cookie disclosure when using IE as a browser

2005-10-31 Thread Jeroen van Wolffelaar
On Mon, Oct 31, 2005 at 09:38:47PM +0100, Moritz Muehlenhoff wrote: > Thijs Kinkhorst wrote: > > After reading that text, I come to the conclusion that this is an issue > > in IE, not in phpBB. The bug is that IE will interpret files of type > > text/jpeg as HTML if they are in fact HTML. Hence, th

Bug#335662: phpbb2: Cookie disclosure when using IE as a browser

2005-10-31 Thread Moritz Muehlenhoff
Thijs Kinkhorst wrote: > After reading that text, I come to the conclusion that this is an issue > in IE, not in phpBB. The bug is that IE will interpret files of type > text/jpeg as HTML if they are in fact HTML. Hence, this is not a bug in > phpBB, but something that affects anything where users

Bug#335662: phpbb2: Cookie disclosure when using IE as a browser

2005-10-31 Thread Thijs Kinkhorst
Hello Moritz, On Tue, 2005-10-25 at 10:54 +0200, Moritz Muehlenhoff wrote: > There's been a report about an exploit for an Internet Explorer > flaw that may lead to disclosure of cookie information. This seems > to be different than #317739. Please see > http://cert.uni-stuttgart.de/archive/bugtr

Bug#335662: phpbb2: Cookie disclosure when using IE as a browser

2005-10-25 Thread Moritz Muehlenhoff
Package: phpbb2 Severity: important Tags: security There's been a report about an exploit for an Internet Explorer flaw that may lead to disclosure of cookie information. This seems to be different than #317739. Please see http://cert.uni-stuttgart.de/archive/bugtraq/2005/10/msg00275.html for mor