Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <575304390.813651275414732700.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Tue, 1 Jun 2010 13:52:12 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: coley <coley@...re.org>
Subject: Re: SFCB vulnerabilities


----- "Nicolas Grégoire" <nicolas.gregoire@...rri.fr> wrote:

> Hi,
> 
> SFCB v1.3.8 fixes two remotely exploitable vulnerabilities (3001896 and
> 3001915 in httpAdapter.c) :
> http://sblim.cvs.sourceforge.net/sblim/sfcb/ChangeLog?view=markup
> 
> CVE-2010-1937 was privately assigned to entry 3001896 but I still don't
> have a CVE id for 3001915. Could you please assign one before I release
> the technical advisory ?
> 

I presuem this is the bug:
http://sourceforge.net/tracker/?func=detail&aid=3001915&group_id=128809&atid=712784

Please use CVE-2010-2054

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.