[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    Re: [oss-security] CVE request: kernel: L2TP send buffer allocation
From:       Josh Bressers <bressers () redhat ! com>
Date:       2010-11-24 13:28:33
Message-ID: 35651733.376061290605313601.JavaMail.root () zmail01 ! collab ! prod ! int ! phx2 ! redhat ! com
[Download RAW message or body]


----- "Dan Rosenberg" <dan.j.rosenberg@gmail.com> wrote:

> There are not overflows in every send/recv call.  The fix that
> addresses these issues in l2tp also addresses any other possible
> examples of this problem in other protocols, including CVE-2010-3859
> (heap overflow in TIPC).
> 

The way CVE handles this is by flaw, not by fix. So if more flaws are found
in other modules, but one fix cover them all, each individual flaw gets its
own ID.

Let me know if this isn't clear.

Thanks.

-- 
    JB
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic