Date: Mon, 26 Oct 2009 14:52:36 +0100 From: Tomas Hoger <thoger@...hat.com> To: oss-security@...ts.openwall.com Cc: "Steven M. Christey" <coley@...us.mitre.org> Subject: Re: More CVE-2009-2408 like issues On Wed, 23 Sep 2009 11:05:17 +0200 Tomas Hoger <thoger@...hat.com> wrote: > On Thu, 3 Sep 2009 16:45:47 +0200 Tomas Hoger <thoger@...hat.com> > wrote: > > > wget - bunch of relevant links are available in here: > > https://bugzilla.redhat.com/show_bug.cgi?id=520454 > > Fixed now in upstream version 1.12: > http://permalink.gmane.org/gmane.comp.web.wget.general/8972 > > This and other mentioned in my previous mail (mutt 1.5.19+, possibly > pre-1.5.19 too, but many are likely to wontfix that; OpenLDAP with > openssl) should probably get CVE. For posterity: - wget got CVE-2009-3490 - mutt CVE-2009-2408-like issue got CVE-2009-3765 - mutt missing name checks in pre-1.5.19 got CVE-2009-3766 (only 1.5.16 is mentioned in the CVE description atm) - openldap got CVE-2009-3767 -- Tomas Hoger / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.