Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 16 Aug 2012 17:22:40 -0400 (EDT)
From: "Steven M. Christey" <>
To: Tomas Hoger <>
cc:,,, John Haxby <>
Subject: Re: MySQL CVEs (was: Security vulnerability in
 MySQL/MariaDB sql/password.c)


I'm really not sure about the best way to handle this.  We definitely want 
to avoid duplicates or triplicates as much as possible.

I of course don't speak for Oracle, but they are generally reluctant to 
comment on CVE mappings or exploit details in any public forum (although 
they have privately provided CVEs to the original researchers if asked). 
I will discuss this issue with them using existing CVE communication 
channels, but I'm not sure when I will have an answer or clarification 
that resolves this complicated interaction between open source and closed 
source philosophies.

Meanwhile, I will ensure that we have updates for the already-assigned 
CVEs that are not covered in Oracle CPUs, and note the *potential* 
duplicates in the descriptions, along with the usual statement that 
emphasizes that Oracle has not commented.

- Steve

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.