oss-sec mailing list archives
Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser
From: Brad Knowles <brad () shub-internet org>
Date: Fri, 24 Jul 2015 16:31:44 -0500
On Jul 24, 2015, at 3:46 PM, Leif Nixon <nixon () lysator liu se> wrote:
I may have been somewhat unclear; what I'm (very) upset about is the release of a working exploit without giving the user community a realistic chance to patch.
Debates over how much to release and when have been with us since the very first security announcement, and they trace their lineage back to the history of physical security going back thousands of years. There will always be people who get their panties in a major twist because they feel that too much information was released too soon, and there will always be people who get their panties in a major twist because not enough information was released soon enough. In this day and age, we have the CRD process. Official representatives from both Qualys and Red Hat have spoken about their perspective on the matter, and they seem to largely be in agreement. So, as a private citizen, you have all the right in the world to get your panties in a major twist because of some huge flaws that you find in the CRD process and how it was executed. Just like every other private citizen who may have something to say on that topic. However, this list is not the proper place to have that flamewar. If you really feel that strongly about it, I suggest that you find the proper place to have a discussion about what CRD really means and how that should be executed. If you can actually help that process to become better, I’m sure that most of the involved parties will welcome your participation. Just keep in mind that this list is not that place. -- Brad Knowles <brad () shub-internet org> LinkedIn Profile: <http://tinyurl.com/y8kpxu>
Attachment:
signature.asc
Description: Message signed with OpenPGP using GPGMail
Current thread:
- Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Qualys Security Advisory (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Leif Nixon (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Philip Pettersson (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Jamie Strandboge (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Kurt Seifried (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Leif Nixon (Jul 24)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Martino Dell'Ambrogio (Jul 24)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Joshua Rogers (Jul 24)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Leif Nixon (Jul 24)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Brad Knowles (Jul 24)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Leif Nixon (Jul 25)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Michal Zalewski (Jul 25)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Dave Horsfall (Jul 25)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Brad Knowles (Jul 25)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Hanno Böck (Jul 26)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Philip Pettersson (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Leif Nixon (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Brandon Perry (Jul 24)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser mancha (Jul 27)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Ankeet Presswala (Jul 27)