Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Mon, 10 Sep 2018 21:07:17 +0200
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Cc: The Apache Security Team <security@...che.org>
Subject: Re: [ANNOUNCE] CVE-2018-11775: ActiveMQ Client - Missing TLS Hostname Verification

Christopher,

On Mon, Sep 10, 2018 at 02:40:05PM -0400, Christopher Shannon wrote:
> Please check the following document and see if you're affected by the issue.
> 
> http://activemq.apache.org/security-advisories.data/CVE-2018-11775-announcement.txt

Thank you for bringing this to oss-security.  However, please be aware
that including essential information only by reference is against list
content guidelines here:

https://oss-security.openwall.org/wiki/mailing-lists/oss-security#list-content-guidelines

which include:

"At least the most essential part of your message (e.g., vulnerability
detail and/or exploit) should be directly included in the message itself
(and in plain text), rather than only included by reference to an
external resource.  Posting links to relevant external resources as well
is acceptable, but posting only links is not.  Your message should
remain valuable even with all of the external resources gone."

To correct this, I've attached the entire text file from the URL above,
with the typo corrected as you mentioned in your follow-up message.

Alexander

View attachment "CVE-2018-11775-announcement.txt" of type "text/plain" (560 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.