oss-sec mailing list archives

Re: CVE Id Request: fetchmail <= 6.3.8 DoS when logging long headers in -v -v mode


From: Jonathan Smith <smithj () freethemallocs com>
Date: Mon, 16 Jun 2008 11:07:01 -0800

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Matthias Andree wrote:
Impeding the 6.3.9 release, there are some nasty bugs that aren't
security relevant which are pending the fix, but are hard to debug.

Are these bugs regressions against 6.3.8? If so, it might make sense to
cherry-pick the security fixes from svn and cut a 6.3.8.1 release with
6.3.8+patches. If not, why let non-regressions hold up 6.3.9?

        smithj

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (GNU/Linux)

iEYEAREIAAYFAkhWudUACgkQCG91qXPaRelIxwCgljo90dSgky/T/FTXCLM4sfRp
/9cAn2hrrcwsuH8a9lIS45z5MiW3IK0c
=D/74
-----END PGP SIGNATURE-----


Current thread: