Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Fri, 23 Oct 2015 17:30:23 -0500
From: Brad Knowles <brad@...b-internet.org>
To: oss-security@...ts.openwall.com
Cc: Brad Knowles <brad@...b-internet.org>
Subject: Re: Duplicate CVE: CVE-2015-7703 in NTP

On Oct 23, 2015, at 4:53 PM, Florian Weimer <fweimer@...hat.com> wrote:

> This is not the case.  <security@....org> was notified on 2015-08-20.
> As the flaws were of low impact and there was no reaction, we disclosed
> the issues here:
> 
>  <http://openwall.com/lists/oss-security/2015/08/25/3>

And I followed that up by taking your post from this list and forwarding that to security@....org on Tue Aug 25 15:42:13 UTC 2015.

If anyone has any security issues with NTP and you would like to discuss things with us privately, our current daily-use operational key is:

sec   3072R/0066B2FD 2015-08-12 [expires: 2017-08-11]
      Key fingerprint = 0E21 6278 E81F 12C9 DD2A  AEF5 AE63 639D 0066 B2FD
uid                  NTP.org Security Team (2015 Daily Use Operational Key) <security@....org>
ssb   3072R/C17304B1 2015-08-12

> I don't know what else we can do to avoid duplicates.

Good question.  Sometimes, you only discover after-the-fact that your XXX is someone else’s YYY, and so you have to be prepared to deal with the occasional collision.

--
Brad Knowles <brad@...b-internet.org>
LinkedIn Profile: <http://tinyurl.com/y8kpxu>


Download attachment "signature.asc" of type "application/pgp-signature" (833 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.