oss-sec mailing list archives

Re: CVE requests: POE::Component::IRC, Alien Arena, Babiloo, Typo3, abcm2ps, ModSecurity, Linux kernel


From: Josh Bressers <bressers () redhat com>
Date: Thu, 30 Sep 2010 15:57:22 -0400 (EDT)


----- "Eugene Teo" <eugene () redhat com> wrote:

On 09/30/2010 12:19 AM, Moritz Muehlenhoff wrote:
Hi Eugene,

On Tue, Sep 28, 2010 at 09:17:48AM +0800, Eugene Teo wrote:
7. Linux kernel (local DoS, impact limited to specific hardware)

http://git.kernel.org/linus/b525c06cdbd8a3963f0173ccd23f9147d4c384b5
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=565790

I emailed this before, please search the archive for subject:
"[oss-security] kernel: thinkpad-acpi: lock down video output
state
access".

Are you suggesting that there was already an assignment (I can't
find one) or that it should not receive one due to limited impact?

http://seclists.org/oss-sec/2010/q2/318

There's no CVE name. I did not request for one, but gave a heads-up
for 
this since it only affects certain specific thinkpads/xorg.



Plese use CVE-2010-3448 for this. Sorry for the misunderstanding.

Thanks.

-- 
    JB


Current thread: