Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20090428112253.2c0fb8e1@redhat.com>
Date: Tue, 28 Apr 2009 11:22:53 +0200
From: Tomas Hoger <thoger@...hat.com>
To: coley@...us.mitre.org
Cc: oss-security@...ts.openwall.com, wietse@...cupine.org
Subject: Re: Re: Some fun with tcp_wrappers

Hi Steve!

On Fri, 24 Apr 2009 19:10:11 -0400 (EDT) "Steven M. Christey"
<coley@...us.mitre.org> wrote:

> Given last week's round of discussion on this list and related
> commentary in Red Hat 491095, I still don't know how to write up
> CVE-2009-0786. Should we focus it on the hosts_ctl() usage in the
> Fedora version of tcp_wrappers?

Given Wietse's (original upstream author) comments, original behavior
is intended one, so 0786 should be rejected.  We're not adding the
change as security fix to the product versions where it's not included
already.

Thank again to Wietse for his comments!

-- 
Tomas Hoger / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.