Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Wed, 10 Jul 2013 09:10:45 -0400 (EDT)
From: Jan Lieskovsky <jlieskov@...hat.com>
To: oss-security@...ts.openwall.com
Cc: "Steven M. Christey" <coley@...us.mitre.org>,
        Marc-André Moreau <marcandre.moreau@...il.com>,
        Bernhard Miklautz <bmiklautz@...nstuff.at>,
        Martin Fleisz <mfleisz@...nstuff.at>
Subject: CVE Request -- FreeRDP: Multiple security fixes in 1.1.0-beta1
 version

Hello Kurt, Steve, vendors,

  (some time ago) FreeRDP upstream has released 1.1.0-beta1 version:
  [1] http://sourceforge.net/mailarchive/message.php?msg_id=30591956

correcting multiple security flaws:
* library / client side fixes:
    https://github.com/FreeRDP/FreeRDP/pull/887
    https://github.com/FreeRDP/FreeRDP/commit/0dc22d5a30a1c7d146b2a835b2032668127c33e9
    https://github.com/FreeRDP/FreeRDP/commit/bceec083677a609ba2f06cc75924ab0accac5388

* server side fixes:
    https://github.com/FreeRDP/FreeRDP/commit/7d58aac24fe20ffaad7bd9b40c9ddf457c1b06e7
    https://github.com/FreeRDP/FreeRDP/commit/0773bb9303d24473fe1185d85a424dfe159aff53

CC-ed Marc-Andre, Bernhard and Martin of FreeRDP upstream to clarify
if the above list of patches is complete wrt to security fixes, corrected
within 1.0.1-beta1 version. Marc-Andre, Bernhard, Martin, please complete
the set of security fixes if / where necessary.

Kurt / Steve, could you allocate CVE ids for these?

Thank you && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team

P.S.: Thanks goes to Florian Weimer of Red Hat Product Security Team for pointing these
      out.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.