Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAHmME9parQruG9aJroLU82J4sX0yodYcPPRks+5XWF4tD2nWpg@mail.gmail.com>
Date: Fri, 2 Oct 2015 15:29:31 +0200
From: "Jason A. Donenfeld" <Jason@...c4.com>
To: oss-security <oss-security@...ts.openwall.com>
Cc: misc <misc@...nsmtpd.org>
Subject: Re: CVE requests: Critical vulnerabilities in OpenSMTPD

I haven't looked at these commits yet but:

If a local user sends a message to a remote address, does this
outgoing connection open up this remote vulnerability vector?

Jason

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.