Re: Bug#905332: debdiff
- To: Christian Fischer <email@example.com>
- Cc: firstname.lastname@example.org, email@example.com
- Subject: Re: Bug#905332: debdiff
- From: firstname.lastname@example.org (Ferenc Wágner)
- Date: Tue, 06 Nov 2018 15:43:30 +0100
- Message-id: <[🔎] email@example.com>
- In-reply-to: <firstname.lastname@example.org> ("Ferenc Wágner"'s message of "Tue, 06 Nov 2018 10:12:29 +0100")
- References: <email@example.com> <handler.905332.B.firstname.lastname@example.org> <email@example.com> <20180803105815.GA30957@pisco.westfalen.local> <firstname.lastname@example.org> <email@example.com> <firstname.lastname@example.org> <email@example.com> <firstname.lastname@example.org>
email@example.com (Ferenc Wágner) writes:
> Christian Fischer <firstname.lastname@example.org> writes:
>> On Fri, 03 Aug 2018 14:42:16 +0200 email@example.com (Ferenc Wágner) wrote:
>>> Unfortunately the CVE hasn't arrived yet; I'll
>>> forward it to you once it does. My acknowledgement mail is of
>>> subject "CVE Request 548000 for CVE ID Request" from
>>> CVE-Request@mitre.org (just for the record).
>> have you received a CVE for this issue yet? Tried to look around in
>> various sources but wasn't able to identify a published CVE for this
>> issue yet.
> I haven't received a CVE for this issue, unfortunately. My original
> request was deflected by Mitre saying that the Apache Software
> Foundation should issue this CVE. However, the Apache webpage states
> that they issue IDs for undisclosed vulnerabilities only. My three
> followup mails asking for clarification remained unanswered by Mitre.
> To add more bad news, according to http://santuario.apache.org/ the just
> released 2.0.2 fixes a very similar bug, which might mean another DoS; I
> couldn't investigate yet. But if it does, we'll need yet another CVE
> for that. I'm sending out some queries.
Shibboleth upstream confirmed that it's basically more of the same
"I would suggest you just attach this to the same CVE as before and
update it to reflect the versions involved."
Dear Security Team, please consider yourselves notified and please
advise how we should track/handle this. I'm looking into backporting
the fix to the stable version 1.7.3-4+deb9u1.