[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] CVE request -- git
From:       Tomas Hoger <thoger () redhat ! com>
Date:       2009-01-23 13:00:39
Message-ID: 20090123140039.054600a9 () redhat ! com
[Download RAW message or body]

On Thu, 22 Jan 2009 17:17:39 -0500 (EST) "Steven M. Christey"
<coley@linus.mitre.org> wrote:

> > Looks like they got texts mixed up.  -5516 was given to git_search
> > issue, and -5517 to git_snapshot and git_object issues (the idea was
> > to use lower id for the issue fixed earlier).  Btw, commitdiff
> > links are correct, only texts need swapping.
> 
> Fixed.

Good, looks better.

> > Can you also change "in 1.5.x" to "before 1.5.x" in both
> > descriptions?
> 
> Done (modulo CVE style).

Plus one extraneous version change ;).  Description for -5516 is
supposed to say "before 1.5.5" (as 1.5.5.0, but upstream does not seem
to use trailing ".0"s in version strings) (I have not looked whether
only 1.5.x were affected by this, this may possibly go back to older
versions), one for -5517 should say "before 1.5.6".  Version difference
was the reason for split / assignment of 2 CVEs.

> > Their announcement mentions version 1.5.6.6, that should have both
> > issues fixed (and -5916).  They'll probably clarify what was their
> > "old" version.
> 
> If they're releasing 1.5.6.6, doesn't that suggest that maybe one of
> the issues were still present in 1.5.5?

Paragraph above should explain this.  Additionally, they probably just
bumped to upstream version that has all three (-5516, -5517, and -5916)
issues fixed.  Not sure what was their previous version though.

HTH

-- 
Tomas Hoger / Red Hat Security Response Team
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic