Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CACYkhxj6Lzg2izRTP4P3bbjLVKtpJRJZiU1vD+ffVN8gzJZUsw@mail.gmail.com>
Date: Mon, 31 Mar 2014 20:31:18 +1100
From: Michael Samuel <mik@...net.net>
To: oss-security@...ts.openwall.com
Subject: Re: CVEs, Crypto and "vulnerabilities"

On 31 March 2014 17:26, Kurt Seifried <kseifried@...hat.com> wrote:
> So the line in the sand is moving currently, I think this issue is
> another good example of something that may qualify for a CVE, or maybe
> not, depends where we draw the line.
>
> https://github.com/opencart/opencart/issues/1279
>
> So if someone has strong opinions either way please speak up.

This looks like an easily exploitable bug.  What possible reason could there
be for it not qualifying?

If somebody wrote an exploit would it be disqualified just because the author
doesn't understand?

Regards,
  Michael

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.