oss-sec mailing list archives

Re: Exim4 MTA CVEs assigned from ZDI


From: Salvatore Bonaccorso <carnil () debian org>
Date: Wed, 4 Oct 2023 21:22:52 +0200

Hi ZDI team,

On Fri, Sep 29, 2023 at 07:26:45PM +0000, zdi () trendmicro com wrote:
Hi,

The ZDI reached out multiple times to the developers regarding
multiple bug reports with little progress to show for it. After our
disclosure timeline was exceeded by many months, we notified the
maintainer of our intent to publicly disclose these bugs, at which
time we were told, "you do what you do." If these bugs have been
appropriately addressed, we will update our advisories with a link
to the security advisory, code check-in, or other public
documentation closing the issue.

As there is still some confusion around the libspf2 related issue: can
you confirm or deny if the issue CVE-2023-42118 / ZDI-23-1472 is
covered by https://github.com/shevek/libspf2/pull/44 ?

Regards,
Salvatore


Current thread: