[VIM] Vendor dispute / researcher retraction: Agavi (CVE-2008-4920)

Steven M. Christey coley at linus.mitre.org
Thu Nov 6 15:40:53 UTC 2008

(also MILW0RM:6970)

The report covered by CVE-2008-4920 is false.  This was for a claimed
directory traversal in Agavi involving the cmplang parameter.  This
parameter does not exist in Agavi.  Further investigation by the vendor
and original researcher show that it is due to a site-specific

See: http://blog.agavi.org/post/58189391/false-agavi-vulnerability-reports

We have been notified by the original vendor as well as the original
researcher.  The researcher has retracted the claim that it is in Agavi.
Since it's site-specific, it is outside CVE's scope, so we're rejecting

- Steve

