Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 25 Feb 2017 12:49:12 -0500
From: Assaf Gordon <assafgordon@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: gnu-paxutils: multiple crashes

Hello,

> On Feb 25, 2017, at 06:36, Agostino Sarubbo <ago@...too.org> wrote:
> 
> Description:
> GNU paxutils is a suite of archive utilities [...]
> A fuzzing on tar and pax shows multiple crashes.
[...]
> Note:
> The email to upstream was rejected.

Not sure what "rejected" means (did the email delivery failed or the maintainer rejected your input, etc).

But generally for GNU Software,
If you don't get timely response from the maintainer,
you can send an email to "security@....org" ,
and if that doesn't help, escalate to "maintainers@....org".
see https://www.gnu.org/software/security/ 

regards,
 - assaf

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.