Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <5432AF52.1050207@redhat.com>
Date: Mon, 06 Oct 2014 09:03:46 -0600
From: Eric Blake <eblake@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: Shellshock timeline (was: CVE-2014-6271: remote
 code execution through bash)

On 10/05/2014 08:11 AM, David A. Wheeler wrote:
> Everyone: Thank you VERY MUCH for your timeline corrections and additions on shellshock.
> 
> My updated document is here:
>   http://www.dwheeler.com/essays/shellshock.html
> The updated timeline is here:
>   http://www.dwheeler.com/essays/shellshock.html#timeline

You list the release of bash43-026 twice, ten hours apart.

You should add the recent release of bash43-030 for CVE-2014-6278:

https://lists.gnu.org/archive/html/bug-bash/2014-10/msg00040.html
5 Oct 2014 19:06:06 -0400

-- 
Eric Blake   eblake redhat com    +1-919-301-3266
Libvirt virtualization library http://libvirt.org


Download attachment "signature.asc" of type "application/pgp-signature" (540 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.