Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 29 Oct 2009 15:35:08 -0500
From: Reed Loden <reed@...dloden.com>
To: oss-security@...ts.openwall.com
Subject: Re: MFSA 2009-63

On Thu, 29 Oct 2009 21:22:44 +0100
Tomas Hoger <thoger@...hat.com> wrote:

> Has anyone been looking into MFSA 2009-63 already trying to figure out
> what really got fixed?  We have some notes in:
> 
>   https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3379
>   https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3377
> 
> but I'm still not quite convinced we have a full list of upstream
> commits that need backporting.  Has anyone got any further already?

What type of specific information are you looking for? Mozilla works
with upstream Xiph.org to get such issues resolved upstream, and then
we either take a minimal fix downstream or a full library upgrade to
latest upstream code. Lately, we've been having to do full library
upgrades due to the complexity of fixes and dependencies on other
changes.

I'll see if we can get those still private bugs concerning the media
library fixes open sooner rather than later, though. I can probably CC
you (and possibly others) to the bugs quicker than that, if it would
help.

~reed
Mozilla Security Group

-- 
Reed Loden - <reed@...dloden.com>

Content of type "application/pgp-signature" skipped

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.