oss-sec mailing list archives
Re: CVE request: lhasa: directory traversals
From: Henri Salo <henri () nerv fi>
Date: Wed, 14 Jan 2015 19:33:54 +0200
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Tue, Jan 13, 2015 at 10:44:00PM +0300, Alexander Cherepanov wrote:
https://github.com/fragglet/lhasa/commit/64b96b5c1d08293b6c373f616b206d951ee358f7 https://github.com/fragglet/lhasa/commit/3bab39fd492a8924bdd25615ef40ca68c0c7ad0f https://github.com/fragglet/lhasa/commit/adcd9912803e69ebeb000cc4c341fbc64820ed1f https://github.com/fragglet/lhasa/commit/c26557dd1b2e640e9785686355c5a2945483460b
All of these commits are only in versions 0.1.0 and 0.2.0 so no need for "incomplete fix for" CVE(s). Use cases would have be nice. - -- Henri Salo -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlS2qIIACgkQXf6hBi6kbk9QGQCgrU3/Ifc9L0uVyi59pYcM8/Hk D/4AniTOUbuCSckMwj9bWPT1TuBl9OUR =ZU0I -----END PGP SIGNATURE-----
Current thread:
- CVE request: lhasa: directory traversals Alexander Cherepanov (Jan 13)
- Re: CVE request: lhasa: directory traversals Henri Salo (Jan 14)
- Re: CVE request: lhasa: directory traversals Alexander Cherepanov (Jan 18)
- Re: CVE request: lhasa: directory traversals Henri Salo (Jan 14)