|
Message-ID: <20130815084657.GA26928@kludge.henri.nerv.fi>
Date: Thu, 15 Aug 2013 11:46:57 +0300
From: Henri Salo <henri@...v.fi>
To: oss-security@...ts.openwall.com
Subject: Re: rubygems insecure download (and other problems)
On Thu, Aug 15, 2013 at 10:37:45AM +0200, Marcus Meissner wrote:
> So the implicit assumption "installing gems is secure" is violated here, which would
> require a CVE I think.
>
> Ciao, Marcus
This deserves CVE. There is already CVEs for similar issues. CVE per software if
I am correct not one CVE for all similar issues.
Kurt, comments?
---
Henri Salo
Download attachment "signature.asc" of type "application/pgp-signature" (199 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.