Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <ZR27jCirFcyI7smg@eldamar.lan>
Date: Wed, 4 Oct 2023 21:22:52 +0200
From: Salvatore Bonaccorso <carnil@...ian.org>
To: oss-security@...ts.openwall.com
Cc: Solar Designer <solar@...nwall.com>, zdi@...ndmicro.com
Subject: Re: Exim4 MTA CVEs assigned from ZDI

Hi ZDI team,

On Fri, Sep 29, 2023 at 07:26:45PM +0000, zdi@...ndmicro.com wrote:
> Hi,
> 
> The ZDI reached out multiple times to the developers regarding
> multiple bug reports with little progress to show for it. After our
> disclosure timeline was exceeded by many months, we notified the
> maintainer of our intent to publicly disclose these bugs, at which
> time we were told, "you do what you do." If these bugs have been
> appropriately addressed, we will update our advisories with a link
> to the security advisory, code check-in, or other public
> documentation closing the issue.

As there is still some confusion around the libspf2 related issue: can
you confirm or deny if the issue CVE-2023-42118 / ZDI-23-1472 is
covered by https://github.com/shevek/libspf2/pull/44 ?

Regards,
Salvatore

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.