Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 2 Oct 2014 18:34:37 +0000
From: Sona Sarmadi <sona.sarmadi@...a.com>
To: "Menkhus, Mark (Global Cyber Security SSRT)" <mark.menkhus@...com>,
	"oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
CC: Solar Designer <solar@...nwall.com>
Subject: RE: more bash parser bugs (CVE-2014-6277,
 CVE-2014-6278)


> What URL do I point to see the security bugs listed by CVE for CVE for bash43-
> 25 through -28?
> 
> I didn't see it in the patches themselves -
> ftp://ftp.cwru.edu/pub/bash/bash-4.3-patches
> 
> Sorry, I am new to bash culture,
> Mark Menkhus
> Hewlett Packard

Mark
Look here (from Michal 's post) for a summary of each CVE and corresponding upstream patches (GNU patches): 
http://www.openwall.com/lists/oss-security/2014/10/02/28 

/Sona

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.