[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: triaging CVE-2016-1503+1504



HI Guido,

On  Mo 25 Jan 2016 20:44:34 CET, Guido Günther wrote:

Hi,
looking at the above CVEs concerning dhcpcd, you wrote

# Remove not-affected tags for squeeze. By simple code inspection we
# cannot say that the issue is not present in squeeze's / wheezy's version
# of dhcpcd. Further actions: try exploit, ask upstream, second opinion.

did you contact upstream about that alread? I don't want to bother them again.
Cheers,
 -- Guido

No, I haven't contacted upstream, yet. Nor have I tried the exploit on dhcpcd in Debian squeeze(-lts).

Greets,
Mike
--

mike gabriel aka sunweaver (Debian Developer)
fon: +49 (1520) 1976 148

GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22  0782 9AF4 6B30 2577 1B31
mail: sunweaver@debian.org, http://sunweavers.net

Attachment: pgpTNAyv9v7f1.pgp
Description: Digitale PGP-Signatur


Reply to: