|
Message-ID: <Pine.GSO.4.51.0804101429380.18291@faron.mitre.org> Date: Thu, 10 Apr 2008 14:31:13 -0400 (EDT) From: "Steven M. Christey" <coley@...us.mitre.org> To: oss-security@...ts.openwall.com Subject: Re: gcc 4.2 optimizations and integer overflow checks On Wed, 9 Apr 2008, Nico Golde wrote: > Hi Steven, > * Steven M. Christey <coley@...us.mitre.org> [2008-04-07 18:24]: > > While an unusual bug, we decided to assign a CVE for it. > [...] > Just stumbled upon CVE-2006-1902, look spretty much the same > to me, is this a dup? Nice find! My immediate suspicion is that they're not the same, based solely on affected versions - CVE-2008-1685 has a specific affected version range because it changed behaviors in 4.2.0. Maybe that change came out of followup analysis stemming from CVE-2006-1902. But, I'm not completely sure. Solar? - Steve
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.