|
Message-ID: <4CE394E3.6020605@gmx.de> Date: Wed, 17 Nov 2010 09:40:03 +0100 From: Matthias Andree <matthias.andree@....de> To: oss-security@...ts.openwall.com Subject: Re: CVE Request -- Mercurial --Doesn't verify subject Common Name properly Am 16.11.2010 17:02, schrieb Marc Deslauriers: > Thanks for the clarification. Here are some more projects that need CVEs > for this issue: > > libcloud: > https://issues.apache.org/jira/browse/LIBCLOUD-55 > https://bugs.launchpad.net/ubuntu/+source/libcloud/+bug/675217 > > Checkbox: > https://bugs.launchpad.net/ubuntu/+source/checkbox/+bug/625076 > > Bazaar: > https://bugs.edge.launchpad.net/bzr/+bug/651161 In the past, Charles Cazabon's getmail would have had to be added to the list, but he didn't care and pointed fingers at the Python library developers, and I'm not sure what the current shape of getmail 4 is, and don't care sufficiently to look it up. Getmail used to happily connect to sites that have expired certs, for instance. -- Matthias Andree
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.