Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 4 Feb 2010 08:25:36 -0500 (EST)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: Eugene Teo <eugene@...hat.com>, Thomas Biege <thomas@...e.de>,
        coley <coley@...re.org>
Subject: Re: KVM possible security issues fixed


----- "Eren Türkay" <eren@...dus.org.tr> wrote:

> On Tuesday 02 February 2010 12:15:54 pm Eugene Teo wrote:
> > Josh wrote some notes here:
> > https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-0297
> 
> Will new CVEs be assigned for these issues? Or they have already been
> assigned?
> 
> usb-linux.c: buffer overflow is CVE-2010-0297 but how about other two,
> slirp and stack corruption.
> 

I'm not comfortable assigning IDs without more details. Those bugs don't
affect Red Hat, so I'm not in a position to spend time on them.

If someone has a decent analysis of the flaws, I'd be happy to hand out
ids, but otherwise I shall defer to MITRE if they want to give out ids for
one line changelog entries.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.