oss-sec mailing list archives

Re: CVE request: vulnerability in FreeRADIUS (OCSP)


From: Stefan Behte <craig () gentoo org>
Date: Tue, 19 Jul 2011 00:06:15 +0200

Hi,

Would you mind sharing that patch with us?

We would be willing to provide the patch to all Linux distributors
but we do not want to release the patch publicly and wait for the
official patch by the packet maintainer of FreeRADIUS.


Then posting it to the new vendor-sec (linux-distros () vs openwall org)
sounds like the right thing to do. Gentoo complies to your requirements
and would like to get the patch directly, if you do not plan to send it
there.

Best regards,

Stefan Behte,
Gentoo Security


Current thread: