oss-sec mailing list archives
Re: CVE-2016-9963 Exim private information leak
From: Heiko Schlittermann <hs () schlittermann de>
Date: Thu, 22 Dec 2016 00:24:09 +0100
Kurt H Maier <khm () sciops net> (Mi 21 Dez 2016 21:59:52 CET): …
To be more precise: On Dec, 25th, at 10.00 UTC we'll push the changes to the public Git repository git://git.exim.org/exim.git and upload the tar balls into the FTP area ftp://ftp.exim.org/pub/exim/exim4Just so we're absolutely clear: You are releasing the fix for a currently-undisclosed security vulnerability on the day most of the Western world's IT staff is on holiday?
Yes. We're addicted to high quality software. And we can't celebrate any holiday while knowing that there are systems outside, that may leak private information. We're very sorry for the unfortunate timeing. We got the vulnerability report on Dec 15th, and requested the CVE on 16th. On 18th the patch was ready and passed our tests. We added 7 days to give the distros a chance to prepare their packages and this made up the 25th. And yes, we know, it is holiday in many countries, maybe in all countries of some of all that many worlds. The decision wasn't an easy one. Delaying some days more would probably hit New Year celebration or Дед Мороз. Delaying it even more? As many users will use their distro's packages, the impact of the update should be very minimal. Probaly they will not even notice it. And if you build your own Exim packages, the effort to rebuild it (4.87.1 is almost the same as 4.87, which you should have running already) is minimal. In case the distros are ready already, we could release on 23rd, but I need feedbeck from the distros and ack from the other developers. I know, it is Christmas Holiday, for me, my kids, and my family too. Best regards from Dresden/Germany Viele Grüße aus Dresden Heiko Schlittermann -- SCHLITTERMANN.de ---------------------------- internet & unix support - Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} - gnupg encrypted messages are welcome --------------- key ID: F69376CE - ! key id 7CBF764A and 972EAC9F are revoked since 2015-01 ------------ -
Attachment:
signature.asc
Description: Digital signature
Current thread:
- CVE Request - Exim 4.69-4.87 - disclosure of private information Heiko Schlittermann (Dec 15)
- Re: CVE Request - Exim 4.69-4.87 - disclosure of private information cve-assign (Dec 15)
- CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 18)
- Re: CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 20)
- Re: CVE-2016-9963 Exim private information leak Kurt H Maier (Dec 21)
- Re: CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 21)
- Re: CVE-2016-9963 Exim private information leak Kurt H Maier (Dec 21)
- Re: CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 22)
- Re: CVE-2016-9963 Exim private information leak Jeffrey Walton (Dec 22)
- Re: CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 22)
- Re: CVE-2016-9963 Exim private information leak Jeffrey Walton (Dec 22)
- CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 18)
- Re: CVE-2016-9963 Exim private information leak Heiko Schlittermann (Dec 22)
- Re: CVE-2016-9963 Exim private information leak Kurt Seifried (Dec 22)
- Re: CVE Request - Exim 4.69-4.87 - disclosure of private information cve-assign (Dec 15)
- Re: CVE-2016-9963 Exim private information leak Johannes Segitz (Dec 22)
- CVE-2016-9963 | Exim 4.87.1 released (Was: CVE Request - Exim 4.69-4.87) - disclosure of private information) Heiko Schlittermann (Dec 25)