|
Message-ID: <CACyjiAjhemrsz-ULTEA_Zf863iGij04Z6Qi+f58MHkEYQ3PP+g@mail.gmail.com> Date: Sat, 26 Apr 2014 17:09:47 +0100 From: Dave Walker <davewalker@...ntu.com> To: oss-security@...ts.openwall.com, kseifried@...hat.com Subject: Re: Ubuntu 14.04: security problem in the lock screen On 26 Apr 2014 16:07, "Kurt Seifried" <kseifried@...hat.com> wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1308572 > > Probably needs a CVE. > > - -- > Kurt Seifried Red Hat Security Response Team (SRT) Hi, This was discovered (and resolved) in pre-release Ubuntu 14.04. Whilst it was only this status by 1 day, the exposure risk is to brave early adopters and developers. Whilst technically it was present in a Unity release, I cannot think of any other consumer of Unity than Ubuntu. As the exposed version of Ubuntu wasn't released, it would seem fair to consider the two together. I am aware that on occasion CVE's have been issued for development snapshots, but I haven't seen clear policy on this. I am not sure if this should be considered widely distributed or not. It would seem redundant to raise a CVE for inflight development snapshot. Unless, you believe the exposure to warrant it? I'm sure someone from Ubuntu Security will chime in, but thought it wise to respond to avoid an ID being raised in potential error. Thanks -- Kind Regards, Dave Walker
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.