Re: [Lightning-dev] CVEs assigned for lightning projects: please upgrade!

2019-09-10 Thread Olaoluwa Osuntokun
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 We've confirmed instances of the CVE being exploited in the wild. If you’re not on the following versions of either of these implementations (these versions are fully patched), then you need to upgrade now to avoid risk of funds loss: * lnd

[Lightning-dev] CVEs assigned for lightning projects: please upgrade!

2019-08-30 Thread Rusty Russell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Security issues have been found in various lightning projects which could cause loss of funds. Full details will be released in 4 weeks (2019-09-27), please uprade well before then. Effected releases: CVE-2019-12998 c-lightning < 0.7.1