oss-sec mailing list archives

Re: CVE id request: apache2


From: Mark J Cox <mjc () redhat com>
Date: Sun, 18 May 2008 16:33:36 +0100 (BST)

can I get a CVE id for:
https://issues.apache.org/bugzilla/show_bug.cgi?id=44975

When used with zlib compression and mod_ssl it is possible
to use a memleak to cause a denial of service.

This already had CVE-2008-1678 reserved for it.

Thanks, Mark
--
Mark J Cox / Red Hat Security Response Team


Current thread: