oss-sec mailing list archives

Re: Why send bugs embargoed to distros?


From: John Haxby <john.haxby () oracle com>
Date: Mon, 25 Sep 2017 09:07:36 +0100

On 23/09/17 12:44, Hanno Böck wrote:
I had informed the distros mailing list one week earlier about the
upcoming disclosure with a bug description and links to the already
available patch.
My understanding is that the purpose of the distros list is that
updates can be prepared so after a disclosure the time between "vuln is
known" and "patch is available" is short.
However from all I can see this largely didn't happen.

This pre-disclosure interval is extremely useful.  We may not, in
general, publish a patch quite as soon after disclosure that I would
like but that doesn't mean we have ignored the pre-disclosure or taken
no action.

While it may not be readily apparent, the distros list does allow us to
get our act together so that when customers come knocking asking "what's
this security problem all about then?" we have answers prepared.  It'll
never be perfect, but I'd like to think we're all getting better at this.

jch


Current thread: