oss-sec mailing list archives

Re: Re: New SMTP smuggling attack


From: Bjoern Franke <bjo () schafweide org>
Date: Fri, 22 Dec 2023 12:23:43 +0100

Hi,


I'm a little confused by sec-consult's process here. They identify a
problem affecting various pieces of software including some very widely
deployed open source software, go to the trouble of doing a coordinated
disclosure, but only do that with...looking at their timeline... gmx,
microsoft and cisco?


they already got some criticism regarding this behaviour:

https://zombofant.net/@jssfr/111618969359339789

https://gay-pirate-assassins.de/@moanos/statuses/01HJ8D8XQ7ZJ89HN4TZFZZ9AS8

Regards


Current thread: