Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4D233932.2080509@summersault.com>
Date: Tue, 04 Jan 2011 10:13:54 -0500
From: Mark Stosberg <mark@...mersault.com>
To: Jan Lieskovsky <jlieskov@...hat.com>
CC: Andy Armstrong <andy@...ten.net>, oss-security@...ts.openwall.com, 
 Marcela Maslanova <mmaslano@...hat.com>,
 Petr Pisar <ppisar@...hat.com>, 
 Chris 'BinGOs' Williams <chris@...gosnet.co.uk>,
 Reed Loden <reed@...dloden.com>, 
 Masahiro Yamada <masa141421356@...il.com>,
 Byron Jones <glob@...b.com.au>, Lincoln Stein <lincoln.stein@...il.com>, 
 Tom spot Callaway <tcallawa@...hat.com>
Subject: Re: Re: CVE Request -- perl-CGI two ids, perl-CGI-Simple
 one id (CVE-2010-3172 already assigned for Bugzilla part)


>   Are there some patches to come yet wrt to Perl's CPAN CGI-Simple module
> and those two CVE ids yet?

Yes, this one. It is not currently applied in the master branch yet:

https://github.com/markstos/CGI--Simple/commit/e811ab874a5e0ac8a99e76b645a0e537d8f714da

> I can see latest CGi-Simple-v113 released on Monday, 27-th December 2010:
> [1] http://search.cpan.org/dist/CGI-Simple/
> 
> Does it contain fixes for both CVE issues (so it is possible to rebase
> to new
> version) or anything else to be done in this part of the world yet?

It contains only a partial fix, mirroring what happened with CGI.pm.

> Is the fix, we were waiting for on the CGI-Simple side:
> [2]
> https://github.com/AndyA/CGI--Simple/commit/5a861280ef524661105e132536ff7d1a9084941f

That's not it, that's separate.

Lincoln is the primary maintainer of CGI.pm, but I have upload rights.
However, we haven't heard from recently. A week ago I asked again for
his input and notified him that I would upload a new release myself I
hadn't heard from him in another week. That time has come now-- I will
plan to upload a new release of CGI.pm in the next 24 hours.

   Mark

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.