Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 29 Jan 2015 07:27:58 +0530
From: Huzaifa Sidhpurwala <>
        Mitre CVE assign department <>
Subject: Re: GHOST gethostbyname() heap overflow in glibc (CVE-2015-0235)

On 01/29/2015 03:17 AM, Florian Weimer wrote:

>> Use CVE-2012-6686 for "unbound alloca use in glob_in_dir" as covered
>> by Red Hat Bugzilla ID 797096.
> Oh, it seems Huzaifa posted the wrong Bugzilla reference.

Yes, sorry wrong bz.

> We still need assignment for this fix:
>   <;a=commitdiff;h=2e96f1c7>
> The matching Red Hat Bugzilla bug is:
>   <>
The above is the correct bug  with the corresponding impact at:


Can we still use the above CVE for this issue?

> I haven't yet seen an upstream bug for it; this change happened before
> upstream required bugs being filed for all user-visible changes.

Huzaifa Sidhpurwala / Red Hat Product Security Team

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ