Date: Thu, 13 Apr 2023 02:07:48 +0100 From: Sam James <sam@...too.org> To: oss-security@...ts.openwall.com Subject: Re: ncurses fixes upstream "Jonathan Bar Or (JBO)" <jobaror@...rosoft.com> writes: > Hello oss-security, > > Our team has worked with the maintainer of the ncurses library (used by several software packages in Linux) to fix several memory corruption vulnerabilities. > They are now fixed at commit 20230408 - see details here (https://invisible-island.net/ncurses/NEWS.html#index-t20230408) > A CVE was assigned (CVE-2023-29491) - it's still under a "reserved" status. > > How can we ensure those fixes get deployed upstream, in major Linux distributions? Try emailing the distributions mailing list at lists.linux.dev too? > We've reached out to Arch, RedHat, Canonical and other popular distros independently. > > Thanks! > JBO Download attachment "signature.asc" of type "application/pgp-signature" (378 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.