Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Thu, 18 Jan 2018 18:02:02 +0100
From: ludo@....org (Ludovic Courtès)
To: Florian Weimer <fweimer@...hat.com>
Cc: oss-security@...ts.openwall.com
Subject: Re: How to deal with reporters who don't want their bugs fixed?

Florian Weimer <fweimer@...hat.com> skribis:

> Subject says it all: What do you do if you receive a vulnerability
> report, and the reporter requests an embargo at some time in the
> future because that's when their paper/conference presentation/patent
> submission is scheduled?

Perhaps you could publicly state upfront that your project will not
accept deadlines put forth by the people who report vulnerabilities
(other than making sure to coordinate with the relevant parties)?

Ludo’.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.