Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20090120103158.7cee6879@redhat.com>
Date: Tue, 20 Jan 2009 10:31:58 +0100
From: Tomas Hoger <thoger@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request -- git

On Tue, 20 Jan 2009 10:11:58 +0100 Sebastian Krahmer <krahmer@...e.de>
wrote:

> > No, they have not.  They fixed both -5516 (git_search) and -5517
> > (git_snapshot and git_object) issues using quote_command() (in their
> > git-1.5.2.4-24.4.src.rpm).  No idea why only one of the CVEs was
> > mentioned in the security report...  They don't seem to include any
> > patch for diff.external issue, or claim to have fixed it.
>
> Only opensuse 11.0 and 11.1 were affected by diff.external
> issue and packages have been released for that.

SUSE-SR:2009:001 only mentions fix for 10.3.  I probably missed other
report mentioning fixes in 11.x.

-- 
Tomas Hoger / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.