Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 27 Feb 2013 13:44:00 -0800
From: Greg KH <greg@...ah.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request - Linux kernel: VFAT slab-based
 buffer overflow

On Wed, Feb 27, 2013 at 10:26:16PM +0100, Yves-Alexis Perez wrote:
> On mer., 2013-02-27 at 10:05 -0800, Greg KH wrote:
> > Yes, I need someone to actually do this.  There used to be a Red Hat
> > security team member that did this, or so I thought.  What happened to
> > that process?  I'll ask on security@...nel.org if someone wants to
> > volunteer to do this, but if not, are you, or anyone else you
> > know/trust
> > willing to do so?
> 
> And do you think it'd be possible to have the same kind of notifications
> for (know security) issues not on security@k.o but committed to the
> tree?

That's the whole problem here, who is going to do such a classification,
and after that, the notification?  The first part is the toughest to do,
as discussed elsewhere in this thread.

greg k-h

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.