Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 30 Apr 2022 19:43:32 +0000
From: Jeremy Stanley <>
Subject: Re: CVE-2022-21449 and version reporting

On 2022-04-28 22:40:23 +0200 (+0200), Sven Schwedas wrote:
> You and Jeremy arguing in bad faith here, OP didn't ask about
> anything like that.

"Bad faith" doesn't mean what you seem to think it means, unless you
really believe I'm shilling for Oracle in order to mislead or
defraud you in some way. I'll tell you straight up, though, I
personally have no connection to Oracle nor have they ever funded my
work in any way.

If you've got concerns with how Oracle handles their vulnerability
reporting, I would take that as an indication to stop using their
software. That's what I do when I don't trust someone. Expecting
MITRE to set some requirements for how everyone is allowed to report
vulnerabilities for unsupported versions of software is not
something I can get behind, though.
Jeremy Stanley

Download attachment "signature.asc" of type "application/pgp-signature" (964 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.