oss-sec mailing list archives

Re: CVE request and heads-up on insecure temp file handling in unpack200 (OpenJDK, Oracle Java)


From: "Vincent Danen" <vdanen () redhat com>
Date: Tue, 04 Feb 2014 09:09:28 -0700

On 02/04/2014, at 7:48 AM, cve-assign () mitre org wrote:

I'm not sure if MITRE will be handling the assignment or if Oracle
will,

We don't want to rule out the possibility that someone from Oracle
will reply to the list and mention that this issue was the topic
of an earlier private report to Oracle, and already has a CVE ID
assigned. In general, MITRE will coordinate with Oracle to avoid a
duplicate assignment.

Fair enough.  That's why I had included Oracle on the cc list, just in case.

Thanks.

-- 
Vincent Danen / Red Hat Security Response Team

Attachment: signature.asc
Description: OpenPGP digital signature


Current thread: