Bug#871617: CVE-2017-3224

2019-02-08 Thread Moritz Mühlenhoff
On Sun, Oct 08, 2017 at 10:12:35PM +1100, Scott Leggett wrote:
> On 2017-09-30.18:24, Moritz Muehlenhoff wrote:
> > On Thu, Aug 10, 2017 at 01:10:46AM +0200, Moritz Muehlenhoff wrote:
> > > Source: quagga
> > > Severity: important
> > > Tags: security
> > > 
> > > Please see http://www.kb.cert.org/vuls/id/793496
> > 
> > What's the status, is that fixed upstream?
> 
> Hi Moritz,
> 
> Sorry I didn't respond earlier on this.
> 
> No, this is not fixed in any version of quagga.
> 
> I have discussed this CVE with upstream and they don't see it as a very
> high impact bug.

Has this been fixed in the mean time?

Cheers,
Moritz



Bug#871617: CVE-2017-3224

2017-10-08 Thread Scott Leggett
On 2017-09-30.18:24, Moritz Muehlenhoff wrote:
> On Thu, Aug 10, 2017 at 01:10:46AM +0200, Moritz Muehlenhoff wrote:
> > Source: quagga
> > Severity: important
> > Tags: security
> > 
> > Please see http://www.kb.cert.org/vuls/id/793496
> 
> What's the status, is that fixed upstream?

Hi Moritz,

Sorry I didn't respond earlier on this.

No, this is not fixed in any version of quagga.

I have discussed this CVE with upstream and they don't see it as a very
high impact bug.

-- 
Regards,
Scott.


signature.asc
Description: PGP signature


Bug#871617: CVE-2017-3224

2017-09-30 Thread Moritz Muehlenhoff
On Thu, Aug 10, 2017 at 01:10:46AM +0200, Moritz Muehlenhoff wrote:
> Source: quagga
> Severity: important
> Tags: security
> 
> Please see http://www.kb.cert.org/vuls/id/793496

What's the status, is that fixed upstream?

> 
> Cheers,
> Moritz
>  
> 



Bug#871617: CVE-2017-3224

2017-08-09 Thread Moritz Muehlenhoff
Source: quagga
Severity: important
Tags: security

Please see http://www.kb.cert.org/vuls/id/793496

Cheers,
Moritz