Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20110719132457.GA25477@openwall.com>
Date: Tue, 19 Jul 2011 17:24:57 +0400
From: Solar Designer <solar@...nwall.com>
To: oss-security@...ts.openwall.com
Cc: dfncert@...-cert.de
Subject: Re: CVE request: vulnerability in FreeRADIUS (OCSP)

On Tue, Jul 19, 2011 at 02:37:46AM +0400, Solar Designer wrote:
> On Tue, Jul 19, 2011 at 12:06:15AM +0200, Stefan Behte wrote:
> > Then posting it to the new vendor-sec (linux-distros@...openwall.org)
> > sounds like the right thing to do.
> 
> This is not exactly the new vendor-sec.  As the name suggests, it is a
> Linux distros only list.  Also, please note that the maximum acceptable
> embargo period on this list is 14 days.  We need to communicate this
> detail to whoever we're asking to disclose anything to the list, before
> they disclose.  When posting to the list, you may encrypt messages to
> the attached key.

I've just described the new list and some of its policies in the newly
added "Linux distribution security contacts list" section at:

http://oss-security.openwall.org/wiki/mailing-lists/vendor-sec

Maybe this will need to be moved to its own wiki page or to a wiki page
on multiple non-historical closed lists if we ever host several at once.
(Non-Linux lists may be setup if there's demand.)

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.