|
Message-ID: <4E3616C9.1070406@kde.org> Date: Sun, 31 Jul 2011 23:00:25 -0400 From: Jeff Mitchell <mitchell@....org> To: oss-security@...ts.openwall.com CC: Josh Bressers <bressers@...hat.com>, KDE Security Team <security@....org>, security@...nokia.com, Tim Brown <timb@...-dimension.org.uk>, "Steven M. Christey" <coley@...us.mitre.org> Subject: Re: CVE: Input validation failure affecting multiple KDE applications, as well as many other Qt-based applications On 07/29/2011 03:53 PM, Josh Bressers wrote: > OK, this one is going to get messy. If you folks want to keep this under > embargo, please contact me in private for IDs (I don't want to try and keep > track on a public list, I'm already unsure what all needs IDs). > > If this isn't terribly serious, it may make the most sense to publish > details so we can figure out how many IDs are needed. Hi Josh, As patches are either being worked on currently or finished for the various affected products that we're aware of, I think we'll get those committed, give the packagers a 48-hour heads-up, and then we'll just put the details on this list. Then you can assign CVEs as appropriate and we can reference those in the various security advisories. Does that sound good? Thanks, Jeff
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.