oss-sec mailing list archives

Re: More CVEs? (was Re: [oss-security] [oCERT-2011-003] multiple implementations denial-of-service via hash algorithm collision)


From: Andrea Barisani <lcars () ocert org>
Date: Fri, 30 Dec 2011 00:00:26 +0100

On Thu, Dec 29, 2011 at 05:55:43PM -0500, David Jorm wrote:

Kurt or other CVE assigners, can you please assign a bunch for
python,
java, tomcat etc. pp.

Tomcat has been assigned CVE-2011-4084.


Indeed, this was referenced in our advisory Timeline but missing in the CVE
list. I just fixed that, sorry for that.

Cheers

Thanks
--
David Jorm / Red Hat Security Response Team

-- 
Andrea Barisani |                Founder & Project Coordinator
          oCERT | OSS Computer Security Incident Response Team

<lcars () ocert org>                         http://www.ocert.org
 0x864C9B9E 0A76 074A 02CD E989 CE7F AC3F DA47 578E 864C 9B9E
        "Pluralitas non est ponenda sine necessitate"


Current thread: