oss-sec mailing list archives

Re: 1.2k bug reports for Debian, some may be security


From: Russ Allbery <rra () stanford edu>
Date: Wed, 26 Jun 2013 22:56:57 -0700

Kurt Seifried <kseifried () redhat com> writes:

I will of course be doing CVEs for these (*sob*). In order to make
this possible though I'm going to need some help in the form of good
CVE requests in this case I will be fascist.

I suspect you will not want to be doing CVEs for most of these.  The ones
I've seen so far aren't really security issues.  They're cases of
command-line programs crashing on input, but usually input that is not
feasibly under the control of an attacker (command-line options provided
by the user, etc.).

My guess is that the vast majority of these problems are robustness
issues, but are not security issues under any reasonable threat model that
I can think of.

-- 
Russ Allbery (rra () stanford edu)             <http://www.eyrie.org/~eagle/>


Current thread: