Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <B6D0ABD4-726C-4036-AECD-D723454609C6@redhat.com>
Date: Thu, 04 Dec 2014 07:40:25 -0700
From: "Vincent Danen" <vdanen@...hat.com>
To: oss-security <oss-security@...ts.openwall.com>
Subject: Re: CVE request: out-of-bounds memory access flaw in
 unrtf

On 12/03/2014, at 9:57 AM, Michal Zalewski wrote:

>>> https://bugzilla.redhat.com/show_bug.cgi?id=1170233>
>> You mixed up Michal and me :-)
>
> Possibly in reference to:
> https://lists.gnu.org/archive/html/bug-unrtf/2014-11/msg00001.html

Wow, I was more tired than I thought.  I did take the wrong reference 
and was indeed referring to Michal's mail.

I've updated our bug to to note both even though it may require more 
than one CVE.  It seems like quite the mess for an unmaintained package.

Thanks for pointing the errors out.


-- 
Vincent Danen / Red Hat Product Security

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.