oss-sec mailing list archives
Re: Podbeuter podcast fetcher: remote code execution
From: Kurt Seifried <kseifrie () redhat com>
Date: Sun, 17 Sep 2017 15:25:53 -0600
I never spoke or advocated about delaying things or timelines and CVEs except in the sense I'd like to make it easier and get CVEs attached to things fast so that issues can be disclosed ASAP, ideally with a CVE. I want to have my cake, and eat it, and share it with everyone else. -Kurt
On Sep 17, 2017, at 10:23, Solar Designer <solar () openwall com> wrote:On Sun, Sep 17, 2017 at 09:59:11AM -0600, Kurt Seifried wrote: many orgs (probably not open source distros run by volunteers, but more big corps) literally do have a clock start ticking when a CVE comes to lightI think that's not a reason to delay disclosing an issue to everyone else until there's a CVE ID. If those orgs have such poor, limited, or maybe cost-saving processes (saving on not needing to bother with issues lacking CVE IDs, no matter how serious), it's their problem and their users'. They deliberately put themselves at a competitive disadvantage. So be it. This only reaffirms me in my suggested approach: public disclosure first, CVE next. So those big corps will have a reason to fix the issues anyway, just with their self-imposed delay. Alexander
Current thread:
- Podbeuter podcast fetcher: remote code execution Alexander Batischev (Sep 16)
- Re: Podbeuter podcast fetcher: remote code execution Solar Designer (Sep 16)
- Re: Podbeuter podcast fetcher: remote code execution Alexander Batischev (Sep 17)
- Re: Podbeuter podcast fetcher: remote code execution Solar Designer (Sep 17)
- Re: Podbeuter podcast fetcher: remote code execution Kurt Seifried (Sep 17)
- Re: Podbeuter podcast fetcher: remote code execution Solar Designer (Sep 17)
- Re: Podbeuter podcast fetcher: remote code execution Kurt Seifried (Sep 17)
- Re: Podbeuter podcast fetcher: remote code execution Alexander Batischev (Sep 17)
- Re: Podbeuter podcast fetcher: remote code execution Solar Designer (Sep 16)