Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CACyjiAjhemrsz-ULTEA_Zf863iGij04Z6Qi+f58MHkEYQ3PP+g@mail.gmail.com>
Date: Sat, 26 Apr 2014 17:09:47 +0100
From: Dave Walker <davewalker@...ntu.com>
To: oss-security@...ts.openwall.com, kseifried@...hat.com
Subject: Re: Ubuntu 14.04: security problem in the lock screen

On 26 Apr 2014 16:07, "Kurt Seifried" <kseifried@...hat.com> wrote:
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1308572
>
> Probably needs a CVE.
>
> - --
> Kurt Seifried Red Hat Security Response Team (SRT)

Hi,

This was discovered (and resolved) in pre-release Ubuntu 14.04. Whilst it
was only this status by 1 day, the exposure risk is to brave early adopters
and developers.

Whilst technically it was present in a Unity release, I cannot think of any
other consumer of Unity than Ubuntu. As the exposed version of Ubuntu
wasn't released, it would seem fair to consider the two together.

I am aware that on occasion CVE's have been issued for development
snapshots, but I haven't seen clear policy on this.

I am not sure if this should be considered widely distributed or not. It
would seem redundant to raise a CVE for inflight development snapshot.
Unless, you believe the exposure to warrant it?

I'm sure someone from Ubuntu Security will chime in, but thought it wise to
respond to avoid an ID being raised in potential error.

Thanks

--
Kind Regards,
Dave Walker

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.