|
Message-ID: <5432AF52.1050207@redhat.com>
Date: Mon, 06 Oct 2014 09:03:46 -0600
From: Eric Blake <eblake@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: Shellshock timeline (was: CVE-2014-6271: remote
code execution through bash)
On 10/05/2014 08:11 AM, David A. Wheeler wrote:
> Everyone: Thank you VERY MUCH for your timeline corrections and additions on shellshock.
>
> My updated document is here:
> http://www.dwheeler.com/essays/shellshock.html
> The updated timeline is here:
> http://www.dwheeler.com/essays/shellshock.html#timeline
You list the release of bash43-026 twice, ten hours apart.
You should add the recent release of bash43-030 for CVE-2014-6278:
https://lists.gnu.org/archive/html/bug-bash/2014-10/msg00040.html
5 Oct 2014 19:06:06 -0400
--
Eric Blake eblake redhat com +1-919-301-3266
Libvirt virtualization library http://libvirt.org
Download attachment "signature.asc" of type "application/pgp-signature" (540 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.