Re: [yocto] bind: issue in trust anchor management can cause named to crash (CVE-2015-1349)

2015-03-13 Thread Sona Sarmadi
Hi Benjamin, > I think this list is not published in the yocto lists page: > https://www.yoctoproject.org/tools-resources/community/mailing-lists > And, who would be able to subscribe to it? invite-only? public? This mailing list is an open list to discuss security related activities (mainly for

Re: [yocto] bind: issue in trust anchor management can cause named to crash (CVE-2015-1349)

2015-03-12 Thread Benjamin Esquivel
cted package to the version which is not vulnerable. > > > > //Sona > > > > From: Alexandru Vaduva [mailto:vaduvajanalexan...@yahoo.com] > Sent: den 12 mars 2015 00:28 > To: Sona Sarmadi; yocto-secur...@yoctoproject.org > Cc: yocto@yoctoproject.org > Subj

Re: [yocto] bind: issue in trust anchor management can cause named to crash (CVE-2015-1349)

2015-03-12 Thread Sona Sarmadi
nd: issue in trust anchor management can cause named to crash (CVE-2015-1349) Wouldn`t it be better for the bugs to be only mentioned on the security list? It is my opinion that know about a risk before it is fixed could cause more harm then good. What do you thing about this?

Re: [yocto] bind: issue in trust anchor management can cause named to crash (CVE-2015-1349)

2015-03-11 Thread Alexandru Vaduva
Wouldn`t it be better for the bugs to be only mentioned on the security list?It is my opinion that know about a risk before it is fixed could cause more harm then good.What do you thing about this? Alex Vaduva On Wednesday, March 11, 2015 10:06 AM, Sona Sarmadi wrote: Affects ver

[yocto] bind: issue in trust anchor management can cause named to crash (CVE-2015-1349)

2015-03-11 Thread Sona Sarmadi
Affects version 9.7.0 - 9.10.1-P1. In master we use bind 9.9.5. // Sona -- ___ yocto mailing list yocto@yoctoproject.org https://lists.yoctoproject.org/listinfo/yocto