oss-sec mailing list archives
Re: FAQ for upstream maintainers
From: Solar Designer <solar () openwall com>
Date: Tue, 19 Feb 2008 20:26:06 +0300
On Mon, Feb 18, 2008 at 11:57:27AM -0900, Jonathan Smith wrote:
Since my main goal (I understand if your goals differ, but they certainly should not conflict) for this list is to provide a way for upstream to coordinate with the vendors, I'm going to start a FAQ or tutorial or whatever dedicated to what upstream should do when they get a report from a user about a security issue. Basic rough draft: http://oss-security.openwall.org/wiki/whattodo I'm sure it can use some cleanup... Ideas, submissions, etc welcome!
I've just applied many minor edits to this page, as well as two important changes: 1. Added the text "... and promptly notify your users of the availability and importance of this new release." This will need to be made more verbose later on - perhaps it deserves its own paragraph (what communication channels may or should exist, etc.) 2. Replaced the suggestion to "... publish it during the embargo with no mention of any security-related impact" with a paragraph that allows such an action if it is absolutely necessary, but discourages it.
Also quite welcome would be someone with wiki-fu prettying up the page :-)
Well, that does not apply to me, so I've only fixed the mailing lists link to be an internal one so far. We could also want to rename this web page to something containing the likely search keywords - and possibly move it to a namespace, which would give a keyword too, once we have a suitable one. "whattodo" is not a likely keyword (or not a closely relevant one). Alexander
Current thread:
- FAQ for upstream maintainers Jonathan Smith (Feb 18)
- Re: FAQ for upstream maintainers Solar Designer (Feb 19)
- Re: FAQ for upstream maintainers Josh Bressers (Feb 20)
- Re: FAQ for upstream maintainers Vincent Danen (Feb 20)
- flaw disclosure (was: FAQ for upstream maintainers) Solar Designer (Feb 24)
- Re: FAQ for upstream maintainers Josh Bressers (Feb 20)
- Re: FAQ for upstream maintainers Solar Designer (Feb 19)