|
Message-ID: <48577C03.3050802@gmx.de> Date: Tue, 17 Jun 2008 10:55:31 +0200 From: Matthias Andree <matthias.andree@....de> To: oss-security@...ts.openwall.com Subject: Re: CVE Id Request: fetchmail <= 6.3.8 DoS when logging long headers in -v -v mode Jonathan Smith schrieb: > Matthias Andree wrote: >> Impeding the 6.3.9 release, there are some nasty bugs that aren't >> security relevant which are pending the fix, but are hard to debug. > > Are these bugs regressions against 6.3.8? If so, it might make sense to > cherry-pick the security fixes from svn and cut a 6.3.8.1 release with > 6.3.8+patches. If not, why let non-regressions hold up 6.3.9? Release overhead; but you're right, I might just make that cut and let 6.3.9 out (since the bugs are long-standing, rather than recent regressions) and postpone fixing of the other bugs to 6.3.10. -- Matthias Andree
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.