Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <CANTw=MPZFn3minGuJ5xPvXLmM9P5LD57Gzg3ABhW+VRhpM+TTQ@mail.gmail.com>
Date: Sun, 7 Apr 2013 21:29:43 -0400
From: Michael Gilbert <mgilbert@...ian.org>
To: oss-security@...ts.openwall.com
Subject: Any info on dovecot CVE-2010-0535?

I'm in the process of reviewing some older untriaged issues in the
Debian security tracker.  I came across this Apple id (CVE-2010-0535)
in dovecot.  Being Apple advisory, there is absolutely no useful
information included, but based on the text, the issue is dependent on
Kerberos.

I found no other dovecot CVEs involving Kerberos, so the question I
have is whether this is still currently an unfixed issue affecting
dovecot?  Was it Apple-specific?  Generally, what can be done by
distro security teams about issues with no actionable information?
Would Mitre be willing to nudge Apple for information?

Best wishes,
Mike

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.