Re: Reporting security vulnerability

2021-02-25 Thread Thomas Wolff
Am 25.02.2021 um 13:57 schrieb Evyatar Gerzi via Cygwin: My apologies again, I am not sure to whom I should address the vulnerability. Because Thomas fixed it in MinTTY but I don't know who is responsible to implement it inside Cygwin. The fix is included in 3.4.6, released as a Cygwin package

Re: Reporting security vulnerability

2021-02-25 Thread Evyatar Gerzi via Cygwin
My apologies again, I am not sure to whom I should address the vulnerability. Because Thomas fixed it in MinTTY but I don't know who is responsible to implement it inside Cygwin. I appreciate your help, thanks, Eviatar Gerzi On Thu, Feb 25, 2021 at 1:10 PM Evyatar Gerzi wrote: > Sorry, I just

Re: Reporting security vulnerability

2021-02-25 Thread Evyatar Gerzi via Cygwin
Sorry, I just noticed that Thomas is one of the authors and he is already familiar with this issue and fixed it. I will send him separate mail and ask him if there is also a fix for Cygwin. Thanks, Eviatar On Thu, Feb 25, 2021 at 12:08 PM Evyatar Gerzi wrote: > Hello, > > I saw that you have a

Re: Reporting security vulnerability

2021-02-25 Thread Adam Dinwoodie
On Thu, 25 Feb 2021 at 10:12, Evyatar Gerzi via Cygwin wrote: > Hello, > > I saw that you have a mailing list for bug reporting but the bug that I > found is a security vulnerability, to whom I need to report it? > I don't know if it is good that it will be "read by many people", but it's > your ca

Reporting security vulnerability

2021-02-25 Thread Evyatar Gerzi via Cygwin
Hello, I saw that you have a mailing list for bug reporting but the bug that I found is a security vulnerability, to whom I need to report it? I don't know if it is good that it will be "read by many people", but it's your call. Thanks, Eviatar Gerzi -- Problem reports: https://cygwin.com/p