Date: Thu, 29 Oct 2009 15:35:08 -0500 From: Reed Loden <reed@...dloden.com> To: oss-security@...ts.openwall.com Subject: Re: MFSA 2009-63 On Thu, 29 Oct 2009 21:22:44 +0100 Tomas Hoger <thoger@...hat.com> wrote: > Has anyone been looking into MFSA 2009-63 already trying to figure out > what really got fixed? We have some notes in: > > https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3379 > https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3377 > > but I'm still not quite convinced we have a full list of upstream > commits that need backporting. Has anyone got any further already? What type of specific information are you looking for? Mozilla works with upstream Xiph.org to get such issues resolved upstream, and then we either take a minimal fix downstream or a full library upgrade to latest upstream code. Lately, we've been having to do full library upgrades due to the complexity of fixes and dependencies on other changes. I'll see if we can get those still private bugs concerning the media library fixes open sooner rather than later, though. I can probably CC you (and possibly others) to the bugs quicker than that, if it would help. ~reed Mozilla Security Group -- Reed Loden - <reed@...dloden.com> Content of type "application/pgp-signature" skipped
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.