Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 14 Sep 2017 14:12:21 +0200
From: Petr Matousek <pmatouse@...hat.com>
To: oss-security@...ts.openwall.com, Armis Security <security@...is.com>
Subject: Re: Linux BlueBorne vulnerabilities

Hi,

On Wed, Sep 13, 2017 at 09:08:31PM +0000, Armis Security wrote:
> We are writing to inform you of two security vulnerabilities we have found
> in the Bluetooth stack in Linux (BlueZ).
> 
> These vulnerabilities have been made public yesterday (Sept. 12, 2017), and
> are part of 8 vulnerabilities we have disclosed to various vendors (as a
> group they are called "BlueBorne").
> 
> Both Linux-related vulnerabilities where disclosed to
> distros@...openwall.org.
> The kernel-related vulnerability (CVE-2017-1000251) was also disclosed to
> security@...nel.org
> Both disclosures began on Sept. 5, 2017, and patches were made available
> yesterday and today.

at https://www.armis.com/blueborne/, "A Coordinated Disclosure"
paragraph you write that:

"Linux - Contacted August 15 and 17, 2017. On September 5, 2017, we
connected and provided the necessary information to the the Linux kernel
security team and to the Linux distributions security contact list and
conversations followed from there. Targeting updates for on or about
September 12, 2017 for coordinated disclosure."

May you please share with us who was contacted on August 15th and 17th
and why you waited until September 5th with the disclosure to
linux-distros and security@...nel.org?

If it was because of the strict embargo rules for linux-distros and
security@...nel.org mailing lists, next time please feel free to reach
Red Hat directly via secalert@...hat.com . We will honour any reporter
set embargo and can contact other vendors directly. And also work on the
fixes.

Thank you,
-- 
Petr Matousek / Red Hat Product Security
PGP: 0xC44977CA 8107 AF16 A416 F9AF 18F3  D874 3E78 6F42 C449 77CA

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.