oss-sec mailing list archives

RE: Exim4 MTA CVEs assigned from ZDI


From: "zdi () trendmicro com" <zdi () trendmicro com>
Date: Wed, 4 Oct 2023 21:01:37 +0000

Hello Salvatore,

We have received a notification from the developers that these issues have been patched. We will be happy to update our 
advisories once they do so.

Thanks,
The ZDI Team

-----Original Message-----
From: Salvatore Bonaccorso <salvatore.bonaccorso () gmail com> On Behalf Of Salvatore Bonaccorso
Sent: Wednesday, October 4, 2023 12:23 PM
To: oss-security () lists openwall com
Cc: Solar Designer <solar () openwall com>; ZDI Researcher Mailbox <zdi () trendmicro com>
Subject: Re: [oss-security] Exim4 MTA CVEs assigned from ZDI

Hi ZDI team,

On Fri, Sep 29, 2023 at 07:26:45PM +0000, zdi () trendmicro com wrote:
Hi,

The ZDI reached out multiple times to the developers regarding
multiple bug reports with little progress to show for it. After our
disclosure timeline was exceeded by many months, we notified the
maintainer of our intent to publicly disclose these bugs, at which
time we were told, "you do what you do." If these bugs have been
appropriately addressed, we will update our advisories with a link
to the security advisory, code check-in, or other public
documentation closing the issue.

As there is still some confusion around the libspf2 related issue: can
you confirm or deny if the issue CVE-2023-42118 / ZDI-23-1472 is
covered by https://github.com/shevek/libspf2/pull/44 ?

Regards,
Salvatore
TREND MICRO EMAIL NOTICE

The information contained in this email and any attachments is confidential and may be subject to copyright or other 
intellectual property protection. If you are not the intended recipient, you are not authorized to use or disclose this 
information, and we request that you notify us by reply mail or telephone and delete the original message from your 
mail system.

For details about what personal information we collect and why, please see our Privacy Notice on our website at: Read 
privacy policy<http://www.trendmicro.com/privacy>


Current thread: