Request for CVEs for Pidgin

Jan Lieskovsky jlieskov at redhat.com
Sat Feb 9 05:47:25 EST 2013


Thank you for the folllow-up, Mark.

----- Original Message -----
> That's for the CVEs!
>

  No problem, you are welcome.

> On Fri, Feb 8, 2013 at 5:24 AM, Jan Lieskovsky <jlieskov at redhat.com> wrote:
>> Fwiw regarding proposed patches, will you post it here once they are
>> available?
>
> Yes.
>
>> Any ETA when it is possible to expect them?
>
> I'm hoping to send out information by the end of the night on Sunday.

When the patches would be available by the end of night on Sunday, would
it be possible the issues to be published one day later? (so we would
have chance to sort out which of the pidgin versions, we ship is
affected by which of the issue and which not, possibly prepare statements
for those not affected etc.) => embargo date to be on Tuesday morning?

>> 
>> Also, regarding reproducers - do you possibly have further information,
>> how these could be reproduced?
>
> I don't.  They're all theoretical, in that we believe they are
> potentially problematic but we have not experienced problems and have
> not tried to reproduce them.

Ok, fair enough. Just needed to check if you possibly
might have some test suites available. No problem.

Thank you && Regards, Jan.
--
Jan iankko Lieskovsky / Red Hat Security Response Team


More information about the security mailing list