[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 28 Apr 2009 11:22:53 +0200
From: Tomas Hoger <thoger@...hat.com>
To: coley@...us.mitre.org
Cc: oss-security@...ts.openwall.com, wietse@...cupine.org
Subject: Re: Re: Some fun with tcp_wrappers
Hi Steve!
On Fri, 24 Apr 2009 19:10:11 -0400 (EDT) "Steven M. Christey"
<coley@...us.mitre.org> wrote:
> Given last week's round of discussion on this list and related
> commentary in Red Hat 491095, I still don't know how to write up
> CVE-2009-0786. Should we focus it on the hosts_ctl() usage in the
> Fedora version of tcp_wrappers?
Given Wietse's (original upstream author) comments, original behavior
is intended one, so 0786 should be rejected. We're not adding the
change as security fix to the product versions where it's not included
already.
Thank again to Wietse for his comments!
--
Tomas Hoger / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ