Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Fri, 11 Oct 2013 19:10:31 +0200
From: Bas Pape <baspape@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE Request - Quassel IRC SQL injection

2013/10/11 Kurt Seifried <kseifried@...hat.com>:
> On 10/09/2013 10:48 AM, Bas Pape wrote:
>> No upstream fix is available at this time, although the below
>> patch does fix the current issue.
>
> Please use CVE-2013-4422 for this issue.

Thanks, glad to see I didn't botch the request. I am correct in
thinking Mitre will fill the details (e.g. description and references)
once they get around to it, or does that require something from my or
upstream's end?

For completeness sake, upstream fixed it [1] and announced a new
release (0.9.1 [2]).

[1] https://github.com/quassel/quassel/commit/aa1008be162cb27da938cce93ba533f54d228869
[2] http://quassel-irc.org/node/120

--
Tucos

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.