[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [SECURITY] bug in contains_dot_dot routine
From: |
Mark J Cox |
Subject: |
Re: [SECURITY] bug in contains_dot_dot routine |
Date: |
Fri, 31 May 2002 16:14:43 +0100 (BST) |
> > Do you have an ETA for this new version?
>
> Sorry, no.
We were about to release the latest tar packages as errata to our
distributions when our QA detected this vulnerability. We don't want to
hold these packages off indefinately - or to release them with a known
flaw. Shall we try to co-ordinate this, or do you not mind if we release
with our patches now?
Cheers, Mark
--
Mark J Cox / Red Hat / OpenSSL / Apache Software Foundation
address@hidden // T: +44 798 061 3110 // F: +44 870 1319174