oss-sec mailing list archives

Re: Closed list


From: Solar Designer <solar () openwall com>
Date: Mon, 2 May 2011 20:12:06 +0400

On Mon, May 02, 2011 at 04:56:30AM -1000, akuster wrote:
On 04/30/2011 04:51 AM, Solar Designer wrote:
<snipped>

Hence, I've saved your subscription request to a separate folder, to
revisit it if a decision is made to start adding "closed" vendors to the
list, if Wind River starts to publish advisories and updates (in other
words, if it becomes no more closed than Red Hat), or if a suitable
separate list is setup.

Can you clarify what is meant by updates?

RHEL-like .src.rpm's or equivalent will do.  Something else might do.

While we're at it, just what software do MontaVista and Wind River ship?
My guess is that embedded Linux distro vendors would not care about
vulnerabilities in desktop-specific apps (e.g., the X server), but I
could be wrong.  And there are other software categories, which may or
may not be relevant.  It'd be nice for potential reporters of security
issues to know which vendors might be affected.

Alexander


Current thread: