|
Bugzilla – Full Text Bug Listing |
| Summary: | overflow in curl | ||
|---|---|---|---|
| Product: | [openSUSE] SUSE Linux 10.1 | Reporter: | Sebastian Krahmer <krahmer> |
| Component: | Network | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | E-mail List <qa-bugs> |
| Severity: | Normal | ||
| Priority: | P5 - None | CC: | mmarek, security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| Whiteboard: | CVE-2006-1061: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) | ||
| Found By: | Other | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Sebastian Krahmer
2006-03-14 09:05:53 UTC
Date: Mon, 13 Mar 2006 13:35:51 -0500 From: Josh Bressers <bressers@redhat.com> To: Ulf Harnhammar <metaur@operamail.com> Cc: vendor-sec@lst.de, daniel@haxx.se, security@gentoo.org, naddy@mips.inka.de Subject: Re: [vendor-sec] cURL tftp:// URL Buffer Overflow > Hello, > > can we have a CAN/CVE id for this issue, please? > > We are considering releasing this information on Saturday this week. Is there anyone on the list that distributes > a vulnerable version of cURL who finds that date inconvenient? Ulf, thanks for the heads up. Saturday (2006-03-18) is probably a bad day for most of us. Can we move it to sometime during the next week (2006-03-20 to 2006-03-24)? Use CVE-2006-1061 for this issue. Thanks. -- JB There's no TFTP support in curl <= 7.14.0, so this does only affect STABLE. Even better. So you only need to fix STABLE and we do not need updates if the fix in STABLE makes it in 10.1 Date: Tue, 14 Mar 2006 12:16:23 +0100 From: Ulf Harnhammar <metaur@operamail.com> To: Josh Bressers <bressers@redhat.com> Cc: vendor-sec@lst.de, daniel@haxx.se, security@gentoo.org, naddy@mips.inka.de Subject: Re: [vendor-sec] cURL tftp:// URL Buffer Overflow > Ulf, thanks for the heads up. Saturday (2006-03-18) is probably a bad day > for most of us. Can we move it to sometime during the next week > (2006-03-20 to 2006-03-24)? OK, let's say Monday the 20th of March, then. > Use CVE-2006-1061 for this issue. Thanks! // Ulf please mention the CRD in your checkin mail so the autobuild team doesn't check it in before the CRD. This means I can submit it now? Ok then. done was checked in -> fixed CVE-2006-1061: CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) |