[<prev month] [next month>] [year] [list]
oss-security mailing list - 2024/04
Messages by day:
April 1 (4 messages)
April 2 (6 messages)
April 3 (17 messages)
April 4 (8 messages)
April 5 (4 messages)
April 7 (1 message)
April 8 (8 messages)
April 9 (17 messages)
April 10 (23 messages)
- Re: xz backdoor prevention using hosts.deny? (Christoph Anton Mitterer <calestyo@...entia.org>)
- Re: xz backdoor prevention using hosts.deny? (Jacob Bachmeyer <jcb62281@...il.com>)
- Re: Is CVE-2024-30203 bogus? (Emacs) (Sean Whitton <spwhitton@...hitton.name>)
- Re: Is CVE-2024-30203 bogus? (Emacs) (Ihor Radchenko <yantar92@...teo.net>)
- Re: Re: Is CVE-2024-30203 bogus? (Emacs) (Salvatore Bonaccorso <carnil@...ian.org>)
- Re: Is CVE-2024-30203 bogus? (Emacs) (Max Nikulin <manikulin@...il.com>)
- CVE-2024-31309: Apache Traffic Server: HTTP/2 CONTINUATION frames
can be utilized for DoS attack (Bryan Call <bcall@...che.org>)
- CVE-2024-31861: Apache Zeppelin: Code injection by Shell
interpreter (Jongyoul Lee <jongyoul@...che.org>)
- Analysis on who is Jia Tan, and who he could work for, reading xz.git (Alejandro Colomar <alx@...nel.org>)
- Re: Analysis on who is Jia Tan, and who he could work for, reading
xz.git (Alejandro Colomar <alx@...nel.org>)
- Re: Analysis on who is Jia Tan, and who he could work for, reading
xz.git (Joey Hess <id@...yh.name>)
- Re: Analysis on who is Jia Tan, and who he could work for, reading xz.git (Solar Designer <solar@...nwall.com>)
- Re: Analysis on who is Jia Tan, and who he could work
for, reading xz.git (Chris Down <chris@...isdown.name>)
- Fwd: Node.js security update for all active relesae lines, April 9
2024 (Rafael Gonzaga <work@...aelgss.dev>)
- NodeJS Command injection via args parameter of child_process.spawn
without shell option enabled on Windows (CVE-2024-27… (Jan Schaumann <jschauma@...meister.org>)
- CERT VU#123335: Multiple Programming Languages Fail to Escape
Arguments Properly in Microsoft Windows (Alan Coopersmith <alan.coopersmith@...cle.com>)
- Re: Analysis on who is Jia Tan, and who he could work for, reading
xz.git (Alejandro Colomar <alx@...nel.org>)
- New Linux LPE via GSMIOC_SETCONF_DLCI? ("Dr. Christopher Kunz" <info@...istopher-kunz.de>)
- Re: Analysis on who is Jia Tan, and who he could work for, reading
xz.git (Vegard Nossum <vegard.nossum@...cle.com>)
- Re: CERT VU#123335: Multiple Programming
Languages Fail to Escape Arguments Properly in Microsoft Windows (Steffen Nurpmeso <steffen@...oden.eu>)
- Re: New Linux LPE via GSMIOC_SETCONF_DLCI? (Solar Designer <solar@...nwall.com>)
- CVE-2024-1086: Linux: nf_tables: use-after-free vulnerability in the nft_verdict_init() function (Solar Designer <solar@...nwall.com>)
- Re: CVE-2024-1086: Linux: nf_tables: use-after-free
vulnerability in the nft_verdict_init() function (Jonathan Wright <jonathan@...alinux.org>)
April 11 (15 messages)
April 12 (11 messages)
April 13 (2 messages)
April 14 (1 message)
April 15 (6 messages)
April 16 (6 messages)
April 17 (10 messages)
April 18 (5 messages)
April 19 (6 messages)
April 20 (3 messages)
April 21 (5 messages)
April 22 (6 messages)
April 23 (6 messages)
April 24 (4 messages)
April 25 (1 message)
April 26 (3 messages)
April 27 (2 messages)
April 28 (4 messages)
April 29 (6 messages)
April 30 (7 messages)
197 messages
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Confused about mailing lists and their use?
Read about mailing lists on Wikipedia
and check out these
guidelines on proper formatting of your messages.