Date: Thu, 2 Oct 2014 06:20:52 +0400 From: Solar Designer <solar@...nwall.com> To: oss-security@...ts.openwall.com Cc: Kohsuke Kawaguchi <kk@...suke.org> Subject: Re: Security advisory in Jenkins On Thu, Oct 02, 2014 at 06:11:27AM +0400, Solar Designer wrote: > Many of these issues were brought to the distros list on Fri Sep 26 > 17:10:16 2014 UTC, and got their CVE IDs assigned there. However, > CVE-2013-2186 was not among those. I don't know why the old CVE ID, > nor how that issue was handled. Looks like it was already public in 2013: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2186 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-2186 (and in many other places). I guess it was just not mentioned in an upstream advisory before, hence the mention now? Alexander
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.