|
Message-ID: <Pine.GSO.4.51.0910162306280.9854@faron.mitre.org> Date: Fri, 16 Oct 2009 23:08:44 -0400 (EDT) From: "Steven M. Christey" <coley@...us.mitre.org> To: oss-security@...ts.openwall.com cc: "Steven M. Christey" <coley@...us.mitre.org> Subject: Re: CVE request: oping allows the disclosure of arbitrary file contents On Fri, 16 Oct 2009, Josh Bressers wrote: > ----- "Julien Tinnes" <julien.tinnes@...il.com> wrote: > > I took a look in the oping source. Without another security flaw, this > is just a bug, oping doesn't do anything while still root that could be > an issue. I agree that it should be fixed, it is a serious bug, but an > attacker cannot do anything nefarious with this flaw. I agree with Josh, this would argue for *not* assigning a CVE, even though it's a serious bug. - Steve
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.