oss-sec: by author

206 messages starting Mar 28 08 and ending Mar 27 08
Date index | Thread index | Author index


Andrea Barisani

project announcement - oCERT - Open Source CERT Andrea Barisani (Mar 28)
Attack vector exploiting rxvt defaulting to :0 Bernhard R. Link (Mar 06)
Re: request CVE id: insecure handling of DISPLAY in rxvt Bernhard R. Link (Mar 28)

Christian Hoffmann

CVE request: lighttpd DoS: forcefully closing of foreign SSL connections Christian Hoffmann (Mar 26)
Re: CVE request: lighttpd DoS: forcefully closing of foreign SSL connections Christian Hoffmann (Mar 28)

Florian Weimer

Re: CVE? CCE? dovecot setting is often used incorrectly Florian Weimer (Mar 08)
Re: CVE request: setrlimit can be avoided (Linux less than 2.6.22) Florian Weimer (Mar 12)

(GalaxyMaster)

Re: subscription-request procedure? (GalaxyMaster) (Feb 19)
Re: subscription-request procedure? (GalaxyMaster) (Feb 19)
Re: wiki (GalaxyMaster) (Feb 18)
Re: wiki page/namespace names, wiki feature requests, etc. (GalaxyMaster) (Feb 25)
wiki page/namespace names (GalaxyMaster) (Feb 25)
Re: wiki (GalaxyMaster) (Feb 18)
Re: extracting patches from SRPMs (Was: code review CVS) (GalaxyMaster) (Feb 21)
Re: wiki - e-mail address obfuscation (GalaxyMaster) (Feb 19)
Re: wiki page/namespace names, wiki feature requests, etc. (GalaxyMaster) (Feb 25)

Hanno Böck

CVEs for zzuf crashers? Hanno Böck (Mar 27)
CVE request: phpmyadmin (PMASA-2008-2) Hanno Böck (Mar 30)
Need CVEs for joomla, egroupware Hanno Böck (Mar 25)
webapp vulns with no cve Hanno Böck (Mar 20)

Jamie Strandboge

CVE request for mysql bug #22413 Jamie Strandboge (Feb 21)

Jim Meyering

subscription-request procedure? Jim Meyering (Feb 19)
Re: subscription-request procedure? Jim Meyering (Feb 20)

Jonathan Smith

CVE? CCE? dovecot setting is often used incorrectly Jonathan Smith (Mar 04)
charter Jonathan Smith (Feb 18)
CVE request: cups Jonathan Smith (Feb 20)
CVE request: lighttpd Jonathan Smith (Feb 22)
CVE request: yet another lighttpd issue Jonathan Smith (Mar 10)
firefox 2.0.0.13 Jonathan Smith (Mar 25)
CVE request: ruby information disclosure Jonathan Smith (Mar 09)
FAQ for upstream maintainers Jonathan Smith (Feb 18)
Re: CVE request: dovecot unauthorized login Jonathan Smith (Mar 10)
Re: welcome Jonathan Smith (Feb 15)
CVE request: dovecot unauthorized login Jonathan Smith (Mar 09)
Re: CVE request for mysql bug #22413 Jonathan Smith (Feb 21)
Re: moderation Jonathan Smith (Feb 21)

Josh Bressers

Re: subscription-request procedure? Josh Bressers (Feb 19)
Re: firefox 2.0.0.13 Josh Bressers (Mar 27)
Re: subscription-request procedure? Josh Bressers (Feb 19)
Re: charter - advisories Josh Bressers (Feb 19)
Re: first spam message on the list Josh Bressers (Feb 21)
CVE Request Josh Bressers (Mar 06)
Re: wiki page/namespace names Josh Bressers (Feb 25)
Re: firefox 2.0.0.13 Josh Bressers (Mar 25)
Re: wiki: links from list archive (was: using oss-security references in CVE) Josh Bressers (Mar 27)
Re: CVE request: bzip2 CERT-FI: 20469 Josh Bressers (Mar 18)
Re: using oss-security references in CVE Josh Bressers (Mar 27)
Re: FAQ for upstream maintainers Josh Bressers (Feb 20)
Re: CVE request: cups Josh Bressers (Feb 20)
Re: wiki page/namespace names, wiki feature requests, etc. Josh Bressers (Feb 25)
Re: CVE request: bzip2 CERT-FI: 20469 Josh Bressers (Mar 19)
Re: CVE Help (CVE request for mysql bug #22413) Josh Bressers (Feb 21)
Re: welcome Josh Bressers (Feb 15)
Re: CVE-2008-0416 for mozilla-firefox; details request Josh Bressers (Feb 21)
Re: welcome Josh Bressers (Feb 16)
Re: wiki Josh Bressers (Feb 18)
Re: charter Josh Bressers (Feb 19)

Kees Cook

Re: code review CVS Kees Cook (Feb 22)
Re: subscription-request procedure? Kees Cook (Feb 19)
Re: code review CVS Kees Cook (Feb 20)
Re: subscription-request procedure? Kees Cook (Feb 19)
Re: subscription-request procedure? Kees Cook (Feb 19)
CVE request: setrlimit can be avoided (Linux less than 2.6.22) Kees Cook (Mar 11)
Re: code review CVS Kees Cook (Feb 21)

Lubomir Kundrak

CVE Request: xine-lib multiple buffer overflows Lubomir Kundrak (Mar 24)
Re: using oss-security references in CVE Lubomir Kundrak (Mar 27)
SA29489 CenterIM URL handling flaw Lubomir Kundrak (Mar 24)
CVE Request: namazu UTF-7 XSS Lubomir Kundrak (Mar 24)
Re: was: SA29489 CenterIM URL handling flaw Lubomir Kundrak (Mar 26)
Re: CVE request: silc Lubomir Kundrak (Mar 28)
CVE Request: Perlbal DoS Lubomir Kundrak (Mar 26)

Ludwig Nussel

CVE request: silc Ludwig Nussel (Mar 28)

Marcus Meissner

CVE ids for Opera 9.26 security update? Marcus Meissner (Feb 28)
new archive file format research by Oulo university Marcus Meissner (Mar 18)
Acrobat Reader 8.1.2 tmp racy wrapper script Marcus Meissner (Feb 21)

Mark J Cox

Re: code review CVS Mark J Cox (Feb 21)
Re: charter Mark J Cox (Feb 19)
Re: charter - advisories Mark J Cox (Feb 25)

Matthieu Herrb

Re: request CVE id: insecure handling of DISPLAY in rxvt Matthieu Herrb (Mar 05)

Micah Anderson

CVE Request: PHP PECL module APC vulnerable to stack-based buffer overflow Micah Anderson (Mar 22)
CVE Request: openssh local users may hijack forwarded X connections Micah Anderson (Mar 22)

Nico Golde

Re: CVE request: vlc Nico Golde (Feb 26)
Re: was: SA29489 CenterIM URL handling flaw Nico Golde (Mar 27)
CVE id request: comix Nico Golde (Mar 31)
was: SA29489 CenterIM URL handling flaw Nico Golde (Mar 25)
Re: was: SA29489 CenterIM URL handling flaw Nico Golde (Mar 25)
Re: Need CVEs for joomla, egroupware Nico Golde (Mar 25)
request CVE id: insecure handling of DISPLAY in rxvt Nico Golde (Mar 04)
Re: request CVE id: insecure handling of DISPLAY in rxvt Nico Golde (Mar 05)
Re: Need CVEs for joomla, egroupware Nico Golde (Mar 25)
Re: using oss-security references in CVE Nico Golde (Mar 27)
Re: request CVE id: insecure handling of DISPLAY in rxvt Nico Golde (Mar 05)
CVE request: insecure X11 handling in ltsp Nico Golde (Mar 11)
CVE request: vlc Nico Golde (Feb 26)
Re: Need CVEs for joomla, egroupware Nico Golde (Mar 25)
Re: CVEs for zzuf crashers? Nico Golde (Mar 27)

Pierre-Yves Rofes

CVE request: multiple issues in ViewVC Pierre-Yves Rofes (Mar 11)
Re: Need CVEs for joomla, egroupware Pierre-Yves Rofes (Mar 25)
Re: code review CVS Pierre-Yves Rofes (Feb 21)

Robert Buchholz

CVE request: policyd-weight insecure temporary file creation Robert Buchholz (Mar 27)
CVE request: GnuPG Import Key Memory Corruption Robert Buchholz (Mar 26)
CVE request: bzip2 CERT-FI: 20469 Robert Buchholz (Mar 18)
Re: CVE? CCE? dovecot setting is often used incorrectly Robert Buchholz (Mar 08)
Re: request CVE id: insecure handling of DISPLAY in rxvt Robert Buchholz (Mar 26)
CVE request: lighttpd mod_cgi script source disclosure Robert Buchholz (Mar 02)
Re: list archive Robert Buchholz (Mar 05)

Sebastian Krahmer

Re: code review CVS Sebastian Krahmer (Feb 18)
code review CVS Sebastian Krahmer (Feb 18)

Solar Designer

flaw disclosure (was: FAQ for upstream maintainers) Solar Designer (Feb 24)
Re: moderation Solar Designer (Feb 21)
list archive Solar Designer (Feb 17)
Re: list archive Solar Designer (Feb 24)
Re: list archive Solar Designer (Feb 24)
Re: wiki Solar Designer (Feb 18)
welcome Solar Designer (Feb 15)
Re: code review CVS Solar Designer (Feb 24)
Re: wiki Solar Designer (Feb 18)
Re: charter - advisories Solar Designer (Feb 24)
wiki Solar Designer (Feb 16)
Re: CVE Help Solar Designer (Feb 22)
Re: wiki - e-mail address obfuscation Solar Designer (Feb 18)
Re: change subscription address Solar Designer (Mar 27)
message Subjects (was: subscription-request procedure?) Solar Designer (Feb 19)
Re: list archive Solar Designer (Mar 05)
Re: using oss-security references in CVE Solar Designer (Mar 27)
wiki: Debian, auditing tools, vendor-sec Solar Designer (Mar 05)
Re: list archive Solar Designer (Feb 18)
Re: subscription-request procedure? Solar Designer (Feb 19)
Re: subscription-request procedure? Solar Designer (Feb 19)
Re: charter - advisories Solar Designer (Feb 19)
Re: wiki - e-mail address obfuscation Solar Designer (Feb 19)
Re: welcome Solar Designer (Feb 16)
wiki: links from list archive (was: using oss-security references in CVE) Solar Designer (Mar 27)
Re: FAQ for upstream maintainers Solar Designer (Feb 19)
Re: list archive Solar Designer (Mar 09)
Re: welcome Solar Designer (Feb 16)
first spam message on the list Solar Designer (Feb 21)

Steve Kemp

Re: wiki: Debian, auditing tools, vendor-sec Steve Kemp (Mar 05)
Re: request CVE id: insecure handling of DISPLAY in rxvt Steve Kemp (Mar 05)
Re: request CVE id: insecure handling of DISPLAY in rxvt Steve Kemp (Mar 04)

Steven M. Christey

Re: CVE request: dovecot unauthorized login Steven M. Christey (Mar 09)
Re: CVE request: insecure X11 handling in ltsp Steven M. Christey (Mar 12)
Re: CVE Request: xine-lib multiple buffer overflows Steven M. Christey (Mar 24)
Re: CVE Request Steven M. Christey (Mar 06)
Re: firefox 2.0.0.13 Steven M. Christey (Mar 26)
Re: CVE Request: Perlbal DoS Steven M. Christey (Mar 27)
Re: CVE request: yet another lighttpd issue Steven M. Christey (Mar 10)
Re: CVE request: lighttpd DoS: forcefully closing of foreign SSL connections Steven M. Christey (Mar 31)
Re: firefox 2.0.0.13 Steven M. Christey (Mar 27)
Re: CVE request: setrlimit can be avoided (Linux less than 2.6.22) Steven M. Christey (Mar 12)
Re: CVE request: GnuPG Import Key Memory Corruption Steven M. Christey (Mar 27)
Re: CVE request for mysql bug #22413 Steven M. Christey (Feb 26)
Re: CVE request: multiple issues in ViewVC Steven M. Christey (Mar 12)
Re: CVE request: vlc Steven M. Christey (Feb 26)
Re: CVE request: phpmyadmin (PMASA-2008-2) Steven M. Christey (Mar 31)
Re: was: SA29489 CenterIM URL handling flaw Steven M. Christey (Mar 27)
Re: CVE request: silc Steven M. Christey (Mar 31)
Re: CVE request: lighttpd Steven M. Christey (Feb 26)
Re: CVE request: dovecot unauthorized login Steven M. Christey (Mar 10)
Re: CVE Help (CVE request for mysql bug #22413) Steven M. Christey (Feb 25)
Re: CVE request: bzip2 CERT-FI: 20469 Steven M. Christey (Mar 18)
Re: webapp vulns with no cve Steven M. Christey (Mar 24)
Re: Need CVEs for joomla, egroupware Steven M. Christey (Mar 27)
Re: CVE request: policyd-weight insecure temporary file creation Steven M. Christey (Mar 31)
Re: Acrobat Reader 8.1.2 tmp racy wrapper script Steven M. Christey (Feb 21)
Re: CVE? CCE? dovecot setting is often used incorrectly Steven M. Christey (Mar 09)
Re: CVE Request: namazu UTF-7 XSS Steven M. Christey (Mar 24)
Re: CVE id request: comix Steven M. Christey (Mar 31)
Re: CVE ids for Opera 9.26 security update? Steven M. Christey (Feb 28)
Re: CVE request: lighttpd mod_cgi script source disclosure Steven M. Christey (Mar 02)
Re: CVE request: dovecot unauthorized login Steven M. Christey (Mar 10)
Re: CVE Request: openssh local users may hijack forwarded X connections Steven M. Christey (Mar 24)
Re: request CVE id: insecure handling of DISPLAY in rxvt Steven M. Christey (Mar 04)
using oss-security references in CVE Steven M. Christey (Mar 27)
Re: CVE Request: PHP PECL module APC vulnerable to stack-based buffer overflow Steven M. Christey (Mar 24)

Thomas Biege

Re: first spam message on the list Thomas Biege (Feb 22)

Tomas Hoger

Re: request CVE id: insecure handling of DISPLAY in rxvt Tomas Hoger (Mar 05)
Re: code review CVS Tomas Hoger (Feb 22)
Re: CVE request: ruby information disclosure Tomas Hoger (Mar 10)

Vincent Danen

Re: wiki Vincent Danen (Feb 17)
Re: wiki Vincent Danen (Feb 19)
CVE-2008-0416 for mozilla-firefox; details request Vincent Danen (Feb 21)
Re: welcome Vincent Danen (Feb 17)
Re: wiki page/namespace names, wiki feature requests, etc. Vincent Danen (Feb 26)
Re: subscription-request procedure? Vincent Danen (Feb 19)
Re: wiki Vincent Danen (Feb 19)
Re: list archive Vincent Danen (Feb 24)
Re: using oss-security references in CVE Vincent Danen (Mar 27)
Re: subscription-request procedure? Vincent Danen (Feb 20)
Re: code review CVS Vincent Danen (Feb 20)
Re: code review CVS Vincent Danen (Feb 20)
Re: list archive Vincent Danen (Feb 17)
Re: code review CVS Vincent Danen (Feb 24)
Re: wiki Vincent Danen (Feb 18)
Re: code review CVS Vincent Danen (Feb 18)
Re: FAQ for upstream maintainers Vincent Danen (Feb 20)
Re: charter - advisories Vincent Danen (Feb 20)
Re: code review CVS Vincent Danen (Feb 21)
Re: first spam message on the list Vincent Danen (Feb 21)
Re: charter Vincent Danen (Feb 19)
Re: charter - advisories Vincent Danen (Feb 24)
Re: wiki Vincent Danen (Feb 18)
Re: wiki page/namespace names, wiki feature requests, etc. Vincent Danen (Feb 26)
Re: firefox 2.0.0.13 Vincent Danen (Mar 25)
Re: list archive Vincent Danen (Feb 19)

Zenaan Harkness

change subscription address Zenaan Harkness (Mar 27)