oss-sec mailing list archives
Re: Running Java across a privilege boundry
From: Solar Designer <solar () openwall com>
Date: Sun, 23 Nov 2014 17:59:42 +0300
Tim, all - On Sat, Nov 22, 2014 at 09:54:18PM +0000, Tim Brown wrote:
I've sent a follow up to distros, which I hope Alexander will approve, to allow the discussion to continue.
It's not like I'm literally "approving" (or not) postings to distros. Yours got to distros list members right after it was received by the server. However, I think it's better discussed on oss-security right away, without use of the distros list. The distros list is for issues where distros are expected to prepare updates during the not-too-long embargo period, and the "instant" availability of updates when the issue is finally made public benefits the end-users in a significant way. I doubt that the issue at hand fits this description. I think almost all of the (relatively few?) systems where this issue matters (where it lets an attacker bypass a privilege boundary, yet no other at least similarly easy and obvious bypass exists and is likely known to the attacker) would probably be slow to update anyway. So far no distro has expressed any interest in having this embargoed. Distros list members: please speak up (here or on the distros list, with Tim CC'ed) if you'd like this embargoed. Tim: if until Tuesday no distro says they want this embargoed, please go ahead and make the issue fully public. (On a related note, I hate it when an issue is sort of "semi-public". It's the worst possible case. When this happens, it's a reason to opt for a shorter embargo period, or for none at all indeed.) If an embargo is requested, please make sure there's an exact date and time for the planned public disclosure. Thanks, Alexander
Current thread:
- Running Java across a privilege boundry Tim Brown (Nov 22)
- Re: Running Java across a privilege boundry Russ Allbery (Nov 22)
- Re: Running Java across a privilege boundry Marc Chadwick (Nov 22)
- Re: Running Java across a privilege boundry Russ Allbery (Nov 22)
- Re: Running Java across a privilege boundry Tim Brown (Nov 22)
- Re: Running Java across a privilege boundry Solar Designer (Nov 23)
- Re: Running Java across a privilege boundry Solar Designer (Nov 25)
- Re: Running Java across a privilege boundry Solar Designer (Dec 08)
- Re: Running Java across a privilege boundry Tim Brown (Dec 18)
- Re: Running Java across a privilege boundry Jakub Wilk (Dec 18)
- Re: Running Java across a privilege boundry Martin Carpenter (Dec 18)
- Re: Running Java across a privilege boundry Jakub Wilk (Dec 18)
- Re: Running Java across a privilege boundry Martin Carpenter (Dec 18)
- Re: Running Java across a privilege boundry Alexander Cherepanov (Dec 18)
- Re: Running Java across a privilege boundry Martin Carpenter (Dec 18)
- Re: Running Java across a privilege boundry Marc Chadwick (Nov 22)
- Re: Running Java across a privilege boundry Russ Allbery (Nov 22)
- Re: Running Java across a privilege boundry Alexander Cherepanov (Dec 18)