|
|
Message-ID: <Pine.GSO.4.51.0807081353030.16947@faron.mitre.org>
Date: Tue, 8 Jul 2008 13:53:48 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: Jonathan Smith <smithj@...ethemallocs.com>
cc: vim_dev@...glegroups.com, "Steven M. Christey" <coley@...us.mitre.org>,
"Charles E Campbell, Jr" <drchip@...pbellfamily.biz>,
oss-security@...ts.openwall.com
Subject: Re: More arbitrary code executions in Netrw version 125, Vim 7.2a.10
On Mon, 7 Jul 2008, Jonathan Smith wrote:
> Steve, could we get CVEs assigned, please? I'd imagine we'd need three;
> one for the tarplugin issue, one for the zipplugin, and one for the
> netrw issues (which are similar enough to probably justify lumping them
> together).
CVE-2008-3074 - tarplugin
CVE-2008-3075 - zipplugin
CVE-2008-3076 - netrw issues
These will be filled in later.
- Steve
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.