Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <Pine.GSO.4.51.0805220159510.15003@faron.mitre.org>
Date: Thu, 22 May 2008 02:01:05 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: oss-security@...ts.openwall.com
cc: Jonathan Smith <smithj@...ethemallocs.com>, chris@...ry.beasts.org
Subject: Re: vsftpd CVE-2007-5962 (Red Hat / Fedora specific)


On Wed, 21 May 2008, Josh Bressers wrote:

> The leak is CVE-2007-5962.  deny_hosts not working did not get a CVE id.

Should it?  If an admin configures deny_hosts in some fashion that vsftpd
doesn't implement correctly, that might be worthy of a CVE.

- Steve

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.