Giuseppe Iuculano wrote:
> Hi Jeroen,
> 
>> These issues have been fixed in Zoph 0.7.0.5 and 0.7.3 and are actually
>> (contrary to what CVE-2008-6837 says) the issues from CVE-2008-3258.
>>
>> I would appreciate it if you could rectify this information.
> 
> Could you provide more details about these issues please?

What kind of information would you like? The issues mentionned in
CVE-2008-6837 are not known to me and because of the limited information
in the report there is no way to determine whether such an issue exists,
the issue in CVE-2008-6838 is the same issue as the one reported in
CVE-2008-3258, which is solved in 0.7.0.5 and 0.7.3.

I very much suspect that these issues have been copied from
http://www.securityfocus.com/bid/30116/info, which describes two issues,
one of which is the same as the one reported in CVE-2008-3258 and the
other is an issue I have not been able to reproduce in any version. This
person has never contacted me about this problem. (I have sent him an
e-mail yesterday, requesting him to rectify this information and contact
me instead of securityfocus next time).

By the way, I did release an update for another security issue yesterday
(that is how I came accross these issues).

Thank you,
Jeroen




-- 
To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to