Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 18 Jun 2013 11:02:17 +0200
From: Florian Weimer <fweimer@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: Thoughts on a vuln/CVE?

On 06/18/2013 08:44 AM, Kurt Seifried wrote:
> However my original question still stands, can/should we consider a
> common configuration of software that goes from being secure to
> insecure to be worthy of a CVE? A lot of things that used to be common
> practice (like shipping every service/server enabled, all accounts
> active, all access enabled, anonymous uploads allowed, etc.) are now
> seen as security vulnerabilities/exposures.

We definitely do.  A recent example is CVE-2012-4446.

-- 
Florian Weimer / Red Hat Product Security Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.