Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 7 Aug 2013 13:23:14 -0400
From: Donald Stufft <donald@...fft.io>
To: kseifried@...hat.com
Cc: oss-security@...ts.openwall.com
Subject: Re: CVE Request: Insecure Software Download in pip


On Jul 31, 2013, at 4:11 AM, Kurt Seifried <kseifried@...hat.com> wrote:

> Ok I have no info on that CVE, is it embargoed? I can't find it in
> google after a quick search. I need to see that one before I can
> assign anything. As for the reserved thing:


This CVE has been fixed, and it is for the issue where pip prior to 1.3 did not download
from the central repository using TLS

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1629

So back to the question of mirroring, possible to get a CVE for that now? :)

-----------------
Donald Stufft
PGP: 0x6E3CBCE93372DCFA // 7C6B 7C5D 5E2B 6356 A926 F04F 6E3C BCE9 3372 DCFA


Content of type "text/html" skipped

Download attachment "signature.asc" of type "application/pgp-signature" (802 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.