Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 13 Nov 2013 23:49:07 -0500
From: Michael Gilbert <mgilbert@...ian.org>
To: oss-security@...ts.openwall.com
Cc: mmcallis@...hat.com
Subject: Re: CVE request: ppthtml heap-based buffer overflow

On Wed, Nov 13, 2013 at 11:11 PM, Murray McAllister wrote:
> (Cc'ing Salvatore in case there is more information in the Debian report
> that I cannot see.)

FYI, there is no non-public information anywhere in the debian bug
tracking system.  Item 3 of the social contract [0] necessitates that
kind of transparency.

Best wishes,
Mike

[0] http://www.debian.org/social_contract

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.