oss-sec mailing list archives

Re: CVE-2014-0235 cleanup


From: Solar Designer <solar () openwall com>
Date: Thu, 3 Jul 2014 11:40:27 +0400

Kurt,

On Thu, Jul 03, 2014 at 01:32:31AM -0600, Kurt Seifried wrote:
https://bugzilla.redhat.com/show_bug.cgi?id=1098222 is for a single
issue, an incomplete fix for CVE-2013-7345.

Please use CVE-2014-3538 for
https://bugzilla.redhat.com/show_bug.cgi?id=1098222

Kurt, please always include (at least one-sentence) CVE descriptions in
your postings.  Not everyone is into CVEs as much as you are, and not
everyone will bother visiting URLs for an issue that is only potentially
relevant to them.  In this case, it's "file: extensive backtracking in
awk rule regular expression".

Thanks,

Alexander


Current thread: