oss-security November 2010 archive
Main Archive Page > Month Archives  > oss-security archives
oss-security: [oss-security] CVE Request: libsdp

[oss-security] CVE Request: libsdp

From: Huzaifa Sidhpurwala <huzaifas_at_nospam>
Date: Tue Nov 16 2010 - 06:44:09 GMT
To: oss-security@lists.openwall.com

Hi,

Leif Nixon reported that libsdp is vulnerable to insecure log file
handling. This is fixed by the latest libsdp version available at:

http://www.openfabrics.org/downloads/libsdp/libsdp-1.1.105-0.4.g1b9b996.tar.gz

More details are available in Red Hat bugzilla:
https://bugzilla.redhat.com/show_bug.cgi?id=647941

Can a CVE id be please assigned to this flaw?

Thanks.

-- Huzaifa Sidhpurwala / Red Hat Security Response Team