Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 9 May 2022 13:46:00 +0400
From: Archange <archange@...ivis.me>
To: Jan Lehnardt <jan@...che.org>
Cc: oss-security@...ts.openwall.com,
 Security CouchDB <security@...chdb.apache.org>
Subject: Re: CVE-2022-24706: Apache CouchDB: Remote Code
 Execution Vulnerability in Packaging

Le 09/05/2022 à 13:41, Jan Lehnardt a écrit :
> Hi Bruno,
>
> first of all, thanks for maintaining CouchDB for Arch. Secondly, for any security related questions, please do not hesitate to contact security@...chdb.apache.org instead of any one of the team individually, as we can’t know if any of is available at all times (vacations and whatnot :)

Sure, you should put this address in copy when posting to oss-security 
then, so you would be sure people reply to that one too. ;)

> As for your questions, see this PR to our packaging infrastructure for how we handle this on Debian and Centos/Rocky: https://github.com/apache/couchdb-pkg/pull/92/files

Thanks, so you use a default env file to set the variable and allow 
people to easily change it in the case of a clustered setup. Will do so 
as well then!

Regards,
Bruno

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.