RE: CVSNT Security Note 5871 (CVE-2010-1326)
"Arthur Barrett" <[email protected]> Thu, 15 Apr 2010 21:47:36 +1100
| Newsgroups | gmane.comp.version-control.cvs.gui.user |
|---|---|
| Message-ID | <[email protected]> |
Jens,
> >>
> >> From the vulnerability description, it sounds like this would
> >> only affect the Windows executables. Is this correct?
> >>
> >
> > Incorrect.
> >
> > I've no idea what in the description led you to that conclusion.
>
> It was the fact that the vulnerability description titles the
> executable as "cvsnt.exe", which seemed to indicate a Windows
> executable...
OK - fair enough. I've clarified that on the web page now.
I believe MITRE require the binary/executable name to make it easier for
sysadmins and security tools vendors to 'search' for affected files on
customer systems. It's clearer now...
Regards,
Arthur Barrett
------------------------------------
Yahoo! Groups Links
<*> To visit your group on the web, go to:
http://groups.yahoo.com/group/cvsgui/
<*> Your email settings:
Individual Email | Traditional
<*> To change settings online go to:
http://groups.yahoo.com/group/cvsgui/join
(Yahoo! ID required)
<*> To change settings via email:
[email protected]
[email protected]
<*> To unsubscribe from this group, send an email to:
[email protected]
<*> Your use of Yahoo! Groups is subject to:
http://docs.yahoo.com/info/terms/