Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <15766132.122498.1295974181252.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Tue, 25 Jan 2011 11:49:41 -0500 (EST)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: coley <coley@...re.org>
Subject: Re: CVE request: multiple gypsy vulnerabilities

I'm giving these 2011 IDs. None of the information was public in 2010.

----- Original Message -----
> Hello,
> 
> I'd like to get CVEs assigned for two issues in Gypsy[1]:
> 
> reads arbitrary files as root user on behalf of regular user
> https://bugs.freedesktop.org/show_bug.cgi?id=33431

Use CVE-2011-0523.

> 
> buffer overflow in nmea device input handling
> https://bugs.freedesktop.org/show_bug.cgi?id=33431
> 

Use CVE-2011-0524.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.