Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20141002022052.GA25523@openwall.com>
Date: Thu, 2 Oct 2014 06:20:52 +0400
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Cc: Kohsuke Kawaguchi <kk@...suke.org>
Subject: Re: Security advisory in Jenkins

On Thu, Oct 02, 2014 at 06:11:27AM +0400, Solar Designer wrote:
> Many of these issues were brought to the distros list on Fri Sep 26
> 17:10:16 2014 UTC, and got their CVE IDs assigned there.  However,
> CVE-2013-2186 was not among those.  I don't know why the old CVE ID,
> nor how that issue was handled.

Looks like it was already public in 2013:

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2186
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-2186

(and in many other places).  I guess it was just not mentioned in an
upstream advisory before, hence the mention now?

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.