oss-sec mailing list archives
Re: Why send bugs embargoed to distros?
From: John Haxby <john.haxby () oracle com>
Date: Mon, 25 Sep 2017 09:07:36 +0100
On 23/09/17 12:44, Hanno Böck wrote:
I had informed the distros mailing list one week earlier about the upcoming disclosure with a bug description and links to the already available patch. My understanding is that the purpose of the distros list is that updates can be prepared so after a disclosure the time between "vuln is known" and "patch is available" is short. However from all I can see this largely didn't happen.
This pre-disclosure interval is extremely useful. We may not, in general, publish a patch quite as soon after disclosure that I would like but that doesn't mean we have ignored the pre-disclosure or taken no action. While it may not be readily apparent, the distros list does allow us to get our act together so that when customers come knocking asking "what's this security problem all about then?" we have answers prepared. It'll never be perfect, but I'd like to think we're all getting better at this. jch
Current thread:
- Why send bugs embargoed to distros? Hanno Böck (Sep 23)
- Re: Why send bugs embargoed to distros? Levente Polyak (Sep 23)
- Re: Why send bugs embargoed to distros? Anthony Liguori (Sep 23)
- Re: Why send bugs embargoed to distros? Simon McVittie (Sep 23)
- Re: Why send bugs embargoed to distros? Marc Deslauriers (Sep 23)
- Re: Why send bugs embargoed to distros? Kurt H Maier (Sep 23)
- Re: Why send bugs embargoed to distros? Till Dörges (Sep 23)
- Re: Why send bugs embargoed to distros? Marcus Meissner (Sep 23)
- Re: Why send bugs embargoed to distros? Ludovic Courtès (Sep 24)
- Re: Why send bugs embargoed to distros? Igor Seletskiy (Sep 24)
- Re: Why send bugs embargoed to distros? John Haxby (Sep 25)
- Re: Why send bugs embargoed to distros? Cliff Perry (Sep 25)
- Re: Why send bugs embargoed to distros? Leo Famulari (Sep 25)
- Re: Why send bugs embargoed to distros? Levente Polyak (Sep 23)