oss-sec mailing list archives
Re: Closed list
From: Tomas Hoger <thoger () redhat com>
Date: Thu, 14 Apr 2011 10:38:52 +0200
Hi Armin! On Wed, 13 Apr 2011 05:59:20 -1000 akuster wrote:
It's clear that one of the membership requirements is now producing security updates.What method of proving this would be acceptable? screen shot, temporary access to our site, public list or other?
A quick idea, rather than a real guidance: Several vendors offer some sort of public CVE database that can be used to search for vendor's updates to address particular flaw. If you're already tagging your updates with CVE ids, this may not be hard to provide. Not because folks on this list ask you to do so, but because it's likely to provide a significant benefit to your customers with little extra cost/effort on top of what you already do. SUSE's database is probably closest to what may work for you as well. CVE info is split by a patched product+version, with links to customer-only download site for the enterprise products. http://support.novell.com/security/cve/ -- Tomas Hoger / Red Hat Security Response Team
Current thread:
- Re: Closed list, (continued)
- Re: Closed list Solar Designer (Apr 30)
- Re: Closed list Jeff Mitchell (Apr 30)
- Re: Closed list Vincent Danen (Apr 13)
- Re: Closed list Solar Designer (Apr 24)
- Re: Closed list Vincent Danen (Apr 26)
- Re: Closed list Josh Bressers (Apr 13)
- Re: Closed list akuster (Apr 13)
- Re: Closed list Dan Rosenberg (Apr 13)
- Re: Closed list akuster (Apr 13)
- Re: Closed list Tomas Hoger (Apr 14)
- Re: Closed list akuster (Apr 14)
- Re: Closed list Solar Designer (Apr 30)
- Re: Closed list akuster (May 02)
- Re: Closed list Solar Designer (May 02)
- Re: Closed list akuster (May 02)
- Re: Closed list Solar Designer (May 02)
- Re: Closed list akuster (May 02)
- Re: [security-vendor] Re: [oss-security] Closed list Mark Hatle (May 02)
- Re: Closed list Solar Designer (May 02)