Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20130705210639.GP28839@betterave.cristau.org>
Date: Fri, 5 Jul 2013 23:06:39 +0200
From: Julien Cristau <jcristau@...ian.org>
To: oss-security@...ts.openwall.com, kseifried@...hat.com
Cc: security@...e.de, Sebastian Krahmer <krahmer@...e.de>
Subject: Re: Question about CVE for X!! DoS

On Fri, Jul  5, 2013 at 14:50:17 -0600, Kurt Seifried wrote:

> http://lists.opensuse.org/opensuse-updates/2013-07/msg00023.html
> https://bugzilla.novell.com/show_bug.cgi?id=815583
> 
> Lists no CVE? I assume it needs one, or did upstream handle this?
> 
If you can connect to an X server, DoSing it is trivial (think
XGrabServer).  This has never been considered a security issue AFAIK.

Cheers,
Julien

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.