On Fri, Dec 14, 2018 at 04:53:06PM +0000, Taylor R Campbell wrote: > There is an exploit being privately circulated, which is what prompted > this discussion in the first place, and an advisory is presumably > forthcoming.
Two local 'exploits', one that had been fixed more than 13 years ago (with proper CVEs), both require careful preparation by the user to be triggered. Isn't that far from 'remote exploit' and 'everyone who can MITM can do that'? -- Michael van Elst Internet: mlel...@serpens.de "A potential Snark may lurk in every tree."