oss-sec mailing list archives

Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser


From: Philip Pettersson <philip.pettersson () gmail com>
Date: Fri, 24 Jul 2015 08:50:49 +0900

On Fri, Jul 24, 2015 at 3:43 AM, Leif Nixon <nixon () lysator liu se> wrote:
Qualys Security Advisory <qsa () qualys com> writes:

Hello, it is July 23, 2015, 17:00 UTC, the Coordinated Release Date for
CVE-2015-3245 and CVE-2015-3246.  Please find our advisory below, and
our exploit attached.

*Why* are you releasing a full exploit just minutes after the patch is
released?

(Disclosure: I am employed by Red Hat, but this is my purely personal question.)

That's how coordinated release dates work. Instead of trying to shame
Qualys for not following your arbitrary views on what is and isn't
"Responsible Disclosure", perhaps you should make sure Red Hat
releases patches hours before the CRD, like Ubuntu does?


Current thread: