RE: CVSNT Security Note 5871 (CVE-2010-1326)

"Arthur Barrett" <[email protected]> Thu, 15 Apr 2010 21:47:36 +1100
Newsgroups gmane.comp.version-control.cvs.gui.user
Message-ID <[email protected]>
Jens,

> >> 
> >> From the vulnerability description, it sounds like this would 
> >> only affect the Windows executables. Is this correct?
> >> 
> > 
> > Incorrect.
> > 
> > I've no idea what in the description led you to that conclusion.
> 
> It was the fact that the vulnerability description titles the 
> executable as "cvsnt.exe", which seemed to indicate a Windows 
> executable...

OK - fair enough.  I've clarified that on the web page now.

I believe MITRE require the binary/executable name to make it easier for
sysadmins and security tools vendors to 'search' for affected files on
customer systems.  It's clearer now...

Regards,


Arthur Barrett


------------------------------------

Yahoo! Groups Links

<*> To visit your group on the web, go to:
    http://groups.yahoo.com/group/cvsgui/

<*> Your email settings:
    Individual Email | Traditional

<*> To change settings online go to:
    http://groups.yahoo.com/group/cvsgui/join
    (Yahoo! ID required)

<*> To change settings via email:
    [email protected] 
    [email protected]

<*> To unsubscribe from this group, send an email to:
    [email protected]

<*> Your use of Yahoo! Groups is subject to:
    http://docs.yahoo.com/info/terms/