Follow us on Twitter or via RSS feeds with tweets or complete announcement texts or excerpts
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 24 May 2011 15:42:31 +0400
From: Michael Tokarev <mjt@....msk.ru>
To: oss-security@...ts.openwall.com
CC: Josh Bressers <bressers@...hat.com>
Subject: Re: CVE Request: exim STARTTLS fix

24.05.2011 15:24, Josh Bressers wrote:
> ----- Original Message -----
>> Hi,
>>
>> while reviewing EXIM git for the last security issues, I also found the
>> STARTTLS fix:
>>
>> http://git.exim.org/exim.git/commitdiff/da80c2a8ed49427334af613c00df65ae301cacdd
>>
>> Is fixed with exim 4.76 apparently.
>>
> 
> That commit suggests it's not an issue, but rather some extra paranoid
> buffer wiping. Is there a reason to believe this is a problem?

Isn't it CVE-2011-0411 attack ?

/mjt

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ