Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 22 Dec 2016 00:24:09 +0100
From: Heiko Schlittermann <hs@...littermann.de>
To: oss-security@...ts.openwall.com
Subject: Re: CVE-2016-9963 Exim private information leak

Kurt H Maier <khm@...ops.net> (Mi 21 Dez 2016 21:59:52 CET):
…
> > To be more precise: On Dec, 25th, at 10.00 UTC we'll push the changes to the public
> > Git repository git://git.exim.org/exim.git and upload the tar balls into the 
> > FTP area ftp://ftp.exim.org/pub/exim/exim4
> 
> Just so we're absolutely clear:
> 
> You are releasing the fix for a currently-undisclosed security
> vulnerability on the day most of the Western world's IT staff is on
> holiday?

Yes. We're addicted to high quality software. And we can't celebrate
any holiday while knowing that there are systems outside, that may leak
private information.

We're very sorry for the unfortunate timeing. We got the vulnerability
report on Dec 15th, and requested the CVE on 16th. On 18th the patch was
ready and passed our tests. We added 7 days to give the distros a chance
to prepare their packages and this made up the 25th.

And yes, we know, it is holiday in many countries, maybe in all
countries of some of all that many worlds.

The decision wasn't an easy one. Delaying some days more would probably
hit New Year celebration or Дед Мороз. Delaying it even more?

As many users will use their distro's packages, the impact of the update
should be very minimal. Probaly they will not even notice it. And if you
build your own Exim packages, the effort to rebuild it (4.87.1 is almost
the same as 4.87, which you should have running already) is minimal.

In case the distros are ready already, we could release on 23rd, but I
need feedbeck from the distros and ack from the other developers.

I know, it is Christmas Holiday, for me, my kids, and my family too.

    Best regards from Dresden/Germany
    Viele Grüße aus Dresden
    Heiko Schlittermann
-- 
 SCHLITTERMANN.de ---------------------------- internet & unix support -
 Heiko Schlittermann, Dipl.-Ing. (TU) - {fon,fax}: +49.351.802998{1,3} -
 gnupg encrypted messages are welcome --------------- key ID: F69376CE -
 ! key id 7CBF764A and 972EAC9F are revoked since 2015-01 ------------ -

Download attachment "signature.asc" of type "application/pgp-signature" (474 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.