Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Mon, 26 Oct 2009 14:52:36 +0100
From: Tomas Hoger <thoger@...hat.com>
To: oss-security@...ts.openwall.com
Cc: "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: More CVE-2009-2408 like issues

On Wed, 23 Sep 2009 11:05:17 +0200 Tomas Hoger <thoger@...hat.com>
wrote:

> On Thu, 3 Sep 2009 16:45:47 +0200 Tomas Hoger <thoger@...hat.com>
> wrote:
> 
> > wget - bunch of relevant links are available in here:
> >   https://bugzilla.redhat.com/show_bug.cgi?id=520454
> 
> Fixed now in upstream version 1.12:
>   http://permalink.gmane.org/gmane.comp.web.wget.general/8972
> 
> This and other mentioned in my previous mail (mutt 1.5.19+, possibly
> pre-1.5.19 too, but many are likely to wontfix that; OpenLDAP with
> openssl) should probably get CVE.

For posterity:
- wget got CVE-2009-3490
- mutt CVE-2009-2408-like issue got CVE-2009-3765
- mutt missing name checks in pre-1.5.19 got CVE-2009-3766 (only 1.5.16
  is mentioned in the CVE description atm)
- openldap got CVE-2009-3767

-- 
Tomas Hoger / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.