|
Message-ID: <20220430194331.k6wx35pjrvoi4qqd@yuggoth.org>
Date: Sat, 30 Apr 2022 19:43:32 +0000
From: Jeremy Stanley <fungi@...goth.org>
To: oss-security@...ts.openwall.com
Subject: Re: CVE-2022-21449 and version reporting
On 2022-04-28 22:40:23 +0200 (+0200), Sven Schwedas wrote:
[...]
> You and Jeremy arguing in bad faith here, OP didn't ask about
> anything like that.
[...]
"Bad faith" doesn't mean what you seem to think it means, unless you
really believe I'm shilling for Oracle in order to mislead or
defraud you in some way. I'll tell you straight up, though, I
personally have no connection to Oracle nor have they ever funded my
work in any way.
If you've got concerns with how Oracle handles their vulnerability
reporting, I would take that as an indication to stop using their
software. That's what I do when I don't trust someone. Expecting
MITRE to set some requirements for how everyone is allowed to report
vulnerabilities for unsupported versions of software is not
something I can get behind, though.
--
Jeremy Stanley
Download attachment "signature.asc" of type "application/pgp-signature" (964 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.