oss-sec mailing list archives
Re: Qualys Security Advisory - The Stack Clash
From: Qualys Security Advisory <qsa () qualys com>
Date: Wed, 21 Jun 2017 15:15:11 -0700
Hi Brad, Theo, all, On Wed, Jun 21, 2017 at 08:25:26AM -0400, Brad Spengler wrote:
OpenBSD publishing this commit ... What's the official explanation for this, and is any action being taken for what I assume is a member of the private list breaking the embargo?
OpenBSD is not a member of distros@, and we therefore contacted them separately: we tried a first time on May 3, then a few times after that, and on May 12 we received a reply. On that same day, and before we sent them our advisory draft (OpenBSD part only), we asked them if they would accept an embargo until May 30, and they accepted. On May 13 they acknowledged receipt of our advisory draft, on May 17 we sent them our proof-of-concept, and on May 18 we were notified by a distros@ member that OpenBSD publicly patched their qsort(), and on May 19 we were notified by another distros@ member that OpenBSD publicly patched their stack guard-page implementation. On May 19 we asked OpenBSD for an explanation as to why they broke the embargo, and on May 21 we received a mail from them but no explanation. However, instead of dwelling on the past, we would like to ask an important question about the future: what should we do the next time we (or other researchers) discover a vulnerability that affects OpenBSD and other operating systems? Will OpenBSD properly enforce the next embargo? Please advise. Thank you very much! With best regards, -- the Qualys Security Advisory team
Current thread:
- Re: Qualys Security Advisory - The Stack Clash, (continued)
- Re: Qualys Security Advisory - The Stack Clash Agostino Sarubbo (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Brad Spengler (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Daniel Micay (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Brad Spengler (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Mike O'Connor (Jun 22)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 24)
- Re: Qualys Security Advisory - The Stack Clash Jeff Law (Jun 23)
- Re: Qualys Security Advisory - The Stack Clash Kurt Seifried (Jun 23)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 24)
- Re: Qualys Security Advisory - The Stack Clash Brad Spengler (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Agostino Sarubbo (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Qualys Security Advisory (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash PaX Team (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Jeff Law (Jun 21)