oss-sec mailing list archives
RE: Exim4 MTA CVEs assigned from ZDI
From: "zdi () trendmicro com" <zdi () trendmicro com>
Date: Wed, 4 Oct 2023 21:01:37 +0000
Hello Salvatore, We have received a notification from the developers that these issues have been patched. We will be happy to update our advisories once they do so. Thanks, The ZDI Team -----Original Message----- From: Salvatore Bonaccorso <salvatore.bonaccorso () gmail com> On Behalf Of Salvatore Bonaccorso Sent: Wednesday, October 4, 2023 12:23 PM To: oss-security () lists openwall com Cc: Solar Designer <solar () openwall com>; ZDI Researcher Mailbox <zdi () trendmicro com> Subject: Re: [oss-security] Exim4 MTA CVEs assigned from ZDI Hi ZDI team, On Fri, Sep 29, 2023 at 07:26:45PM +0000, zdi () trendmicro com wrote:
Hi, The ZDI reached out multiple times to the developers regarding multiple bug reports with little progress to show for it. After our disclosure timeline was exceeded by many months, we notified the maintainer of our intent to publicly disclose these bugs, at which time we were told, "you do what you do." If these bugs have been appropriately addressed, we will update our advisories with a link to the security advisory, code check-in, or other public documentation closing the issue.
As there is still some confusion around the libspf2 related issue: can you confirm or deny if the issue CVE-2023-42118 / ZDI-23-1472 is covered by https://github.com/shevek/libspf2/pull/44 ? Regards, Salvatore TREND MICRO EMAIL NOTICE The information contained in this email and any attachments is confidential and may be subject to copyright or other intellectual property protection. If you are not the intended recipient, you are not authorized to use or disclose this information, and we request that you notify us by reply mail or telephone and delete the original message from your mail system. For details about what personal information we collect and why, please see our Privacy Notice on our website at: Read privacy policy<http://www.trendmicro.com/privacy>
Current thread:
- Re: Exim4 MTA CVEs assigned from ZDI Heiko Schlittermann (Oct 01)
- Re: Exim4 MTA CVEs assigned from ZDI Heiko Schlittermann (Oct 01)
- Re: Exim4 MTA CVEs assigned from ZDI Heiko Schlittermann (Oct 02)
- Re: Exim4 MTA CVEs assigned from ZDI Heiko Schlittermann (Oct 02)
- New Exim security release 4.96.2 (was: Exim4 MTA CVEs assigned from ZDI) Heiko Schlittermann (Oct 15)
- Re: Exim4 MTA CVEs assigned from ZDI Heiko Schlittermann (Oct 02)
- Re: Exim4 MTA CVEs assigned from ZDI Heiko Schlittermann (Oct 01)
- <Possible follow-ups>
- Re: Exim4 MTA CVEs assigned from ZDI Salvatore Bonaccorso (Oct 04)
- RE: Exim4 MTA CVEs assigned from ZDI zdi () trendmicro com (Oct 04)
- Re: Exim4 MTA CVEs assigned from ZDI Fabian Keil (Oct 04)
- Re: Exim4 MTA CVEs assigned from ZDI Heiko Schlittermann (Oct 05)
- Re: Exim4 MTA CVEs assigned from ZDI Solar Designer (Oct 05)
- RE: Exim4 MTA CVEs assigned from ZDI zdi () trendmicro com (Oct 05)
- Re: Exim4 MTA CVEs assigned from ZDI Salvatore Bonaccorso (Oct 05)
- Re: Exim4 MTA CVEs assigned from ZDI Cory McIntire (Oct 05)
- RE: Exim4 MTA CVEs assigned from ZDI zdi () trendmicro com (Oct 04)