On Tue, 26 Jul 2011, Dag Wieers wrote:

> I don't agree with this, yum segfaulting is something that should be
> fixed, regardless of how people are using it. Anyone interested to report
> this to get a CVE ? ;-)

1. build an exploit reproducer

2. file a bug showing the potential, valid configuration is 
exploitable in the Red hat tracker, setting the security 
matter flag on

3. cc me in on the bug ... you watch my RH tracker bug 
activities presently as I recall, and so have the account 
details, and I'll upstream the request to MITRE if Red Hat 
does not

best regards,

-- Russ herrold
_______________________________________________
users mailing list
[email protected]
http://lists.repoforge.org/mailman/listinfo/users

Reply via email to