Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <Pine.GSO.4.51.0910162306280.9854@faron.mitre.org>
Date: Fri, 16 Oct 2009 23:08:44 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: oss-security@...ts.openwall.com
cc: "Steven M. Christey" <coley@...us.mitre.org>
Subject: Re: CVE request: oping allows the disclosure of 
 arbitrary file contents


On Fri, 16 Oct 2009, Josh Bressers wrote:

> ----- "Julien Tinnes" <julien.tinnes@...il.com> wrote:
>

> I took a look in the oping source. Without another security flaw, this
> is just a bug, oping doesn't do anything while still root that could be
> an issue. I agree that it should be fixed, it is a serious bug, but an
> attacker cannot do anything nefarious with this flaw.

I agree with Josh, this would argue for *not* assigning a CVE, even though
it's a serious bug.

- Steve

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.