oss-sec mailing list archives
Re: Re: Some fun with tcp_wrappers
From: "Steven M. Christey" <coley () linus mitre org>
Date: Wed, 15 Apr 2009 20:44:49 -0400 (EDT)
I'm not sure how to handle this from a CVE perspective, except: - if the API functions perform as documented, as Wietse says, then separate CVEs would need to be assigned for applications that misuse the API. - If there is a separate bug that causes tcp_wrappers to allow hosts in ways that are contrary to specification, then that would be treated as a problem in tcp_wrappers (whether it's from Wietse or some downstream modification). - If there's a problem due to incomplete documentation, that's a somewhat unique case for CVE that would require more thought (although not a first occurrence since Apple had a bad-documentation bug a year or two ago) Jan and Tomas - Red Hat bug 491095 mentions CVE-2009-0786 but I'm not clear on how to write it up given the state of the discussion at this point. - Steve
Current thread:
- Some fun with tcp_wrappers Tomas Hoger (Apr 15)
- Re: Some fun with tcp_wrappers Wietse Venema (Apr 15)
- Re: Re: Some fun with tcp_wrappers Tomas Hoger (Apr 15)
- Re: Re: Some fun with tcp_wrappers Wietse Venema (Apr 15)
- Re: Re: Some fun with tcp_wrappers Tomas Hoger (Apr 15)
- Re: Re: Some fun with tcp_wrappers Wietse Venema (Apr 15)
- Re: Re: Some fun with tcp_wrappers Wietse Venema (Apr 15)
- Re: Re: Some fun with tcp_wrappers Steven M. Christey (Apr 15)
- Re: Re: Some fun with tcp_wrappers Tomas Hoger (Apr 16)
- Re: Re: Some fun with tcp_wrappers Wietse Venema (Apr 16)
- Re: Re: Some fun with tcp_wrappers Tomas Hoger (Apr 16)
- Re: Re: Some fun with tcp_wrappers Wietse Venema (Apr 16)
- Re: Re: Some fun with tcp_wrappers Steven M. Christey (Apr 24)
- Re: Re: Some fun with tcp_wrappers Tomas Hoger (Apr 28)
- Re: Re: Some fun with tcp_wrappers Tomas Hoger (Apr 15)
- Re: Some fun with tcp_wrappers Wietse Venema (Apr 15)
- Re: Re: Some fun with tcp_wrappers Tomas Hoger (Apr 16)
- Re: Re: Some fun with tcp_wrappers Wietse Venema (Apr 16)