oss-sec mailing list archives
Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead
From: Amos Jeffries <squid3 () treenet co nz>
Date: Tue, 23 Jul 2019 01:09:40 +1200
On 22/07/19 11:50 pm, Solar Designer wrote:
On Mon, Jul 22, 2019 at 12:29:53PM +0100, Stuart Henderson wrote:On 2019/07/22 11:21, Mikhail Klementev wrote:Kindly notice that this is a public mail list.The sender is clearly aware of this, see the timeline.Exactly. It's just an unusual disclosure process that involves giving the users a heads-up a few days before public disclosure of the actual vulnerabilities and fixes. So far, this process is practiced by OpenSSL and Exim (any others?) Unfortunately, this keeps confusing people, which is why this time Heiko's message starts with "Note: EMBARGO is still in effect". Judging by Mikhail's reply, this wasn't good enough to avoid confusion, and I don't know what would be
IMHO the key difference between the two is the initial impression one gets from the message layout. This Exim message looks just like any other full-detail disclosure report. It takes time to read the text and clicking through to the repository links to realize that this is not actually leaking code changes and detail about the issue. The OpenSSL is just a warning that a new version X is about to land. People who care are left to do their own research into where to get it. The distro teams who need the warning already know that. AYJ
Attachment:
signature.asc
Description: OpenPGP digital signature
Current thread:
- CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Heiko Schlittermann (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Mikhail Klementev (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Stuart Henderson (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Mikhail Klementev (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Solar Designer (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Amos Jeffries (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Ian Zimmerman (Jul 22)
- Security release pre-announcement messages Douglas Bagnall (Jul 24)
- Re: Security release pre-announcement messages Stiepan (Jul 26)
- Re: Security release pre-announcement messages Greg KH (Jul 26)
- Re: Security release pre-announcement messages Greg KH (Jul 26)
- Re: Security release pre-announcement messages Stiepan (Jul 26)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Stuart Henderson (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Mikhail Klementev (Jul 22)
- Re: CVE-2019-13917 OVE-20190718-0006: Exim: security release ahead Heiko Schlittermann (Jul 22)