[<prev] [next>] [<thread-prev] [thread-next>] [month] [year] [list]
Date: Fri, 11 Sep 2009 08:20:15 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: Tomas Hoger <thoger@...hat.com>
cc: oss-security@...ts.openwall.com, coley@...us.mitre.org
Subject: Re: CVE id request: silc-toolkit
On Fri, 11 Sep 2009, Tomas Hoger wrote:
> On Thu, 3 Sep 2009 12:45:46 -0400 (EDT) "Steven M. Christey"
> <coley@...us.mitre.org> wrote:
>
> > Use CVE-2009-3051 for both of these format strings, to be filled in
> > later.
>
> Looks like this actually got split to two after all...
>
> CVE-2009-3051:
Sorry for forgetting to tell everyone about this. One of our CVE analysts
did some deeper investigation and noticed that there was a clear break in
affected versions, so we decided that a split was reasonable. This
distinction wasn't immediately obvious to me when processing the initial
ID request.
- Steve
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ