Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CALx_OUBSE1NYimVDhToGgxdx6hwaRZJ3DwEYFZ62GXLzfU4nXw@mail.gmail.com>
Date: Tue, 8 Apr 2014 22:51:41 -0700
From: Michal Zalewski <lcamtuf@...edump.cx>
To: oss-security@...ts.openwall.com
Cc: Jussi Eronen <juhani.eronen@...ora.fi>
Subject: Re: OpenSSL 1.0.1 TLS/DTLS hearbeat information
 disclosure CVE-2014-0160

I find it somewhat perplexing that Codenomicon apparently had time to
register the vanity domain two days before pinging the vendor (or
rather unnecessarily, having CERT do it on their behalf).

> Domain Name: HEARTBLEED.COM
> Creation Date: 2014-04-05 15:13:33
> [...]
> Mon, 07 Apr 2014 ~15:30: NCSC-FI reports issue to OpenSSL

/mz

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.