oss-sec mailing list archives

Re: SFCB vulnerabilities


From: Josh Bressers <bressers () redhat com>
Date: Tue, 1 Jun 2010 13:52:12 -0400 (EDT)


----- "Nicolas Grégoire" <nicolas.gregoire () agarri fr> wrote:

Hi,

SFCB v1.3.8 fixes two remotely exploitable vulnerabilities (3001896 and
3001915 in httpAdapter.c) :
http://sblim.cvs.sourceforge.net/sblim/sfcb/ChangeLog?view=markup

CVE-2010-1937 was privately assigned to entry 3001896 but I still don't
have a CVE id for 3001915. Could you please assign one before I release
the technical advisory ?


I presuem this is the bug:
http://sourceforge.net/tracker/?func=detail&aid=3001915&group_id=128809&atid=712784

Please use CVE-2010-2054

Thanks.

-- 
    JB


Current thread: