[Secure-testing-commits] r14793 - data/CVE

Michael Gilbert michael.s.gilbert at gmail.com
Fri Jun 4 15:20:58 UTC 2010


On Fri, Jun 4, 2010 at 6:24 AM, Moritz Muehlenhoff wrote:
> - two further "issues" in glibc. I don't think we need to treat them
>  as security problems, since attacker-controllable format strings
>  cannot be handled securely anyway. I've marked them as unimportant.
>  Aurelien, if you disgree simply adjust the severity.

if the other three glibc issues are going to be fixed in lenny,
perhaps these should be as well?  maybe no-dsa would be a better tag
for now.

mike



More information about the Secure-testing-commits mailing list