Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 26 Apr 2016 17:26:48 -0400
From:      Shawn Webb <shawn.webb@hardenedbsd.org>
To:        Kristof Provost <kp@FreeBSD.org>
Cc:        src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-head@freebsd.org, secteam@freebsd.org
Subject:   Re: svn commit: r298664 - head/sys/fs/msdosfs
Message-ID:  <20160426212648.GC13055@mutt-hardenedbsd>
In-Reply-To: <116F3C09-CD22-42EC-80BF-4EAD6CA1C824@FreeBSD.org>
References:  <201604262036.u3QKaWto038435@repo.freebsd.org> <20160426210138.GA13055@mutt-hardenedbsd> <2190C480-1B7A-47F8-BFB4-D7C8E6F25385@FreeBSD.org> <20160426211804.GB13055@mutt-hardenedbsd> <116F3C09-CD22-42EC-80BF-4EAD6CA1C824@FreeBSD.org>

next in thread | previous in thread | raw e-mail | index | archive | help

--7qSK/uQB79J36Y4o
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Tue, Apr 26, 2016 at 11:22:32PM +0200, Kristof Provost wrote:
>=20
> > On 26 Apr 2016, at 23:18, Shawn Webb <shawn.webb@hardenedbsd.org> wrote:
> > Was secteam@ even involved, then? Seems like a user-facing kernel buffer
> > overflow ought to have involved secteam@.
> >=20
> No, it wasn???t. This bug had been open for quite a while, and I just hap=
pend to see the report and look at it.

Now CC'ing secteam@. I'm wondering if a CVE should be filed. Or, at the
very least, a FreeBSD Security Advisory.

Thanks,

--=20
Shawn Webb
HardenedBSD

GPG Key ID:          0x6A84658F52456EEE
GPG Key Fingerprint: 2ABA B6BD EF6A F486 BE89  3D9E 6A84 658F 5245 6EEE

--7qSK/uQB79J36Y4o
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJXH90XAAoJEGqEZY9SRW7ufiMP/j/hEb6/bnYByK7pnh6cPACm
SWlGU3lpkpEAmwL6YNVmv2b/USi+PbVYAD/fFvM7pdlETzB5QA9JpQsIQ0Vzrsbd
xgxTVjJs6pQe9A1mgHmi7HcFs3hB2atXapzEbbl4IvSkQB9pw9bFo/YaruM07wOB
GoflLRuFRvTKzZu+tSTf6bMjC4+BjtKiJRzC4r/EmzsD8WWy2febFr+Km3hfLcL2
nYjj0g5tmUY3J2AEGkbA32oBBU5x/rLouG6+9Mnox4359i6dNo9maXw2ph5LG8Jj
cuD9By9mbBB4wn9/cYDTlYK8JzUt6gXPjL8PiXLbyX/le1aYzTboHQe5r0iS16q3
Mi8+VKtowyr/tOCq/n2X8mwBOcQzdp6w35e50vAW5fttKREZvvz9kB+dUdrWkvBy
8jPjIjTc60dErQVIyeDdVbAUi2WljnjYd/deDKIXCC6Z9G8Ftdsz0y+5UQRlHQs1
LghQfO5kolfMevZ/svNed14xVF1BY9DPstiNMrtunbC6hjikx8DP+9lPgPGKNJ5I
vTLVdghvkltjHUOfUaeyCCZO84RDpki8rG+TCSrgN5jbP4MF7f8szPoiSWIKoeBT
UrjSXGRgd2Ev0hkRh1lN1bTKoKq8Ygb+sptRNCzwBi7L2kYJGPqaTHXgQ+KU4uK2
VwEGOvpJBjEZ6sw8wKJu
=KA2d
-----END PGP SIGNATURE-----

--7qSK/uQB79J36Y4o--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20160426212648.GC13055>