Date: Wed, 10 Apr 2013 12:21:14 -0400 From: Michael Gilbert <mgilbert@...ian.org> To: oss-security@...ts.openwall.com Subject: Re: Any info on dovecot CVE-2010-0535? On Mon, Apr 8, 2013 at 7:02 PM, Geoff Keating wrote: > On 07/04/2013, at 6:29 pm, Michael Gilbert <mgilbert@...ian.org> wrote: > >> I'm in the process of reviewing some older untriaged issues in the >> Debian security tracker. I came across this Apple id (CVE-2010-0535) >> in dovecot. Being Apple advisory, there is absolutely no useful >> information included, but based on the text, the issue is dependent on >> Kerberos. >> >> I found no other dovecot CVEs involving Kerberos, so the question I >> have is whether this is still currently an unfixed issue affecting >> dovecot? Was it Apple-specific? > > Hi Michael, > > This is Apple-specific. It affects the db-od auth method. Thank you very much for the information. >> Generally, what can be done by >> distro security teams about issues with no actionable information? >> Would Mitre be willing to nudge Apple for information? > > Apple's on this list so you can always just ask... Good to know, thank you for participating. Best wishes, Mike
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.