Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead

Related Vulnerabilities: CVE-2019-13917  
                							

                <!--X-Body-Begin-->
<!--X-User-Header-->

oss-sec
mailing list archives
<!--X-User-Header-End-->
<!--X-TopPNI-->

By Date

By Thread

</form>

<!--X-TopPNI-End-->
<!--X-MsgBody-->
<!--X-Subject-Header-Begin-->
Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead

<!--X-Subject-Header-End-->
<!--X-Head-of-Message-->

From: Heiko Schlittermann &lt;hs () schlittermann de&gt;

Date: Mon, 22 Jul 2019 22:33:15 +0200

<!--X-Head-of-Message-End-->
<!--X-Head-Body-Sep-Begin-->

<!--X-Head-Body-Sep-End-->
<!--X-Body-of-Message-->
Eric,

Eric Blake &lt;eblake () redhat com&gt; (Mo 22 Jul 2019 15:28:33 CEST):

Perhaps part of the confusion stems from:

t0: Thu Jul 18 2019
    - this notice to distros () vs openwall org and exim-maintainers () exim org
    - open limited access to our security Git repo. See below.

This statement makes it sound like the fix can be downloaded by anyone
that knows about the git repo containing the fix...

Yes, blame on me. I missed to redact that part of the message.

Or even the choice of tense in this paragraph may help: it sounds like
past tense ("is the officially released version") even though at the
time of the email it is a future tense ("will become the officially
released version").

Thank you for your hints. Even I hope, we won't have a "next time", next
time I'll try to improve the wording/grammer of the messages I send.

    Best regards from Dresden/Germany
    Viele Grüße aus Dresden
    Heiko Schlittermann
--
 SCHLITTERMANN.de ---------------------------- internet &amp; unix support -
 Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
 gnupg encrypted messages are welcome --------------- key ID: F69376CE -
 ! key id 7CBF764A and 972EAC9F are revoked since 2015-01 ------------ -
Attachment:
signature.asc
Description: 

<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->

<!--X-Follow-Ups-End-->
<!--X-References-->
<!--X-References-End-->
<!--X-BotPNI-->

By Date

By Thread

Current thread:

Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead, (continued)

Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Solar Designer (Jul 22)
Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Amos Jeffries (Jul 22)

Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Ian Zimmerman (Jul 22)

Security release pre-announcement messages Douglas Bagnall (Jul 24)
Re: Security release pre-announcement messages Stiepan (Jul 26)
Re: Security release pre-announcement messages Greg KH (Jul 26)
Re: Security release pre-announcement messages Greg KH (Jul 26)
Re: Security release pre-announcement messages Stiepan (Jul 26)

Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Heiko Schlittermann (Jul 22)

Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Eric Blake (Jul 22)

Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Heiko Schlittermann (Jul 22)

Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Solar Designer (Jul 26)

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->