oss-sec mailing list archives

Re: Tunnel Blick: Multiple Vulnerabilities to Local Root and DoS (OS X)


From: Kyle Creyts <kyle.creyts () gmail com>
Date: Sat, 11 Aug 2012 08:54:55 -0700

Has he also met all conditions for requesting CVEs for these
vulnerabilities?
On Aug 11, 2012 8:46 AM, "Solar Designer" <solar () openwall com> wrote:

On Sat, Aug 11, 2012 at 05:31:23PM +0200, Jason A. Donenfeld wrote:
Tunnel Blick, a popular OpenVPN manager for Macintosh, has several
vulnerabilities in an SUID helper. I'm not sure if this is the place
to report vulnerabilities in Macintosh software, but Tunnel Blick is
open source.

I just want to confirm that this is on-topic (since Open Source) and
desirable, as long as you also notify the maintainers (which you did).

Thanks,

Alexander


Current thread: