Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 17 Jun 2008 10:55:31 +0200
From: Matthias Andree <matthias.andree@....de>
To: oss-security@...ts.openwall.com
Subject: Re: CVE Id Request: fetchmail <= 6.3.8 DoS when	logging
 long headers in -v -v mode

Jonathan Smith schrieb:
> Matthias Andree wrote:
>> Impeding the 6.3.9 release, there are some nasty bugs that aren't
>> security relevant which are pending the fix, but are hard to debug.
> 
> Are these bugs regressions against 6.3.8? If so, it might make sense to
> cherry-pick the security fixes from svn and cut a 6.3.8.1 release with
> 6.3.8+patches. If not, why let non-regressions hold up 6.3.9?

Release overhead; but you're right, I might just make that cut and let
6.3.9 out (since the bugs are long-standing, rather than recent
regressions) and postpone fixing of the other bugs to 6.3.10.

-- 
Matthias Andree

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.