|
Message-Id: <A797FBF7-DB96-4641-9263-9EF8C6C6A7D5@stufft.io> Date: Wed, 7 Aug 2013 13:23:14 -0400 From: Donald Stufft <donald@...fft.io> To: kseifried@...hat.com Cc: oss-security@...ts.openwall.com Subject: Re: CVE Request: Insecure Software Download in pip On Jul 31, 2013, at 4:11 AM, Kurt Seifried <kseifried@...hat.com> wrote: > Ok I have no info on that CVE, is it embargoed? I can't find it in > google after a quick search. I need to see that one before I can > assign anything. As for the reserved thing: This CVE has been fixed, and it is for the issue where pip prior to 1.3 did not download from the central repository using TLS https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1629 So back to the question of mirroring, possible to get a CVE for that now? :) ----------------- Donald Stufft PGP: 0x6E3CBCE93372DCFA // 7C6B 7C5D 5E2B 6356 A926 F04F 6E3C BCE9 3372 DCFA Content of type "text/html" skipped Download attachment "signature.asc" of type "application/pgp-signature" (802 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.