oss-sec mailing list archives

Re: CVE id request: fraud2


From: "Steven M. Christey" <coley () linus mitre org>
Date: Wed, 24 Sep 2008 14:03:26 -0400 (EDT)


On Wed, 24 Sep 2008, Robert Buchholz wrote:

CVE-2008-4201 states "in FAAD2 before 2.6.1", whereas the patch is based
on 2.6.1 -- i.e. 2.6.1 is affected. So the CVE needs to be corrected.

I inferred 2.6.1 incorrectly because that was the latest version available
for download.  THanks for the correction.

- Steve


Current thread: