Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CANTw=MOqq1-irLVrj+_dxsRvNCu-7ACY-4YBXAH6awL_C4AAXA@mail.gmail.com>
Date: Fri, 4 May 2012 14:25:06 -0400
From: Michael Gilbert <mgilbert@...ian.org>
To: oss-security@...ts.openwall.com
Subject: Re: Debian/Ubuntu php_crypt_revamped.patch

On Fri, May 4, 2012 at 2:18 PM, Daniel Kahn Gillmor wrote:
> On 05/04/2012 01:35 PM, Solar Designer wrote:
>> The purpose [is] to notify Ubuntu and others of the Debian bug
>> that they may need to fix in Debian-derived distros, and to suggest that
>> the patch be dropped from future versions.
>
> If your goal is to get the patch dropped from Debian and Debian-derived
> distributions, the most reliable way to do that is to file a bug against
> the Debian php packages explaining your reasons for that.

Security issue reporters are usually not held responsible for
reporting the issues that they find to every affected distribution
themselves.  That is why common id numbers (CVEs) are important.  They
give us a common reference for every problem.  Then its the job of
those of us representing such distributions to pass the information on
to the appropriate tracking systems within our own focus areas.

Best wishes,
Mike

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.