Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <52972005.217119.1314043426149.JavaMail.root@zmail01.collab.prod.int.phx2.redhat.com>
Date: Mon, 22 Aug 2011 16:03:46 -0400 (EDT)
From: Josh Bressers <bressers@...hat.com>
To: oss-security@...ts.openwall.com
Cc: Moritz Mühlenhoff <jmm@...til.org>,
        coley <coley@...re.org>
Subject: Re: CVE request: Pidgin crash



----- Original Message -----
> 2011/8/22 Moritz Mühlenhoff <jmm@...til.org>:
> > On Mon, Aug 22, 2011 at 02:55:34AM -0400, Huzaifa Sidhpurwala wrote:
> >> Hi Mark,
> >>
> >> >Hi! Would it be possible to issue a CVE for a new crash in Pidgin?
> >>
> >> >http://pidgin.im/news/security/?id=53
> >>
> >> Please use CVE-2011-2942 for this issue.
> >>
> >> Also looking at http://pidgin.im/news/security it seems two other
> >> security issues were also fixed in 2.10.0, do you want CVEs to be
> >> assigned for them as well?
> >
> > Please do. Since they're published in the form of upstream advisories
> > we'd like to properly track them in the Debian Security Tracker.
> 
> That's fine by me. As an upstream developer I don't feel like I have a
> strong incentive to obtain a CVE. But if it's helpful to packagers, than
> sure.
> 
> The two issues in question are discussed here:
> http://pidgin.im/news/security/?id=54

This is a MSN crash. Use CVE-2011-3184


> http://pidgin.im/news/security/?id=55
> 
> The second one only affects Pidgin on Microsoft Windows.
> 

Use CVE-2011-3185 for this.

Thanks.

-- 
    JB

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.