Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20141209020725.GA27278@openwall.com>
Date: Tue, 9 Dec 2014 05:07:25 +0300
From: Solar Designer <solar@...nwall.com>
To: Tim Brown <tmb@...35.com>
Cc: oss-security@...ts.openwall.com
Subject: Re: Running Java across a privilege boundry

Distros -

Tim is not responding to my ping's about making the issue public. :-(
Can someone from the distros list, preferably from a distro who actually
bothered to handle the issue (did anyone?) make the issue public ASAP,
by posting in here?  Please.  Thanks.

Alexander

On Wed, Nov 26, 2014 at 06:54:48AM +0300, Solar Designer wrote:
> On Sun, Nov 23, 2014 at 05:59:41PM +0300, Solar Designer wrote:
> > So far no distro has expressed any interest in having this embargoed.
> > 
> > Distros list members: please speak up (here or on the distros list, with
> > Tim CC'ed) if you'd like this embargoed.
> > 
> > Tim: if until Tuesday no distro says they want this embargoed, please go
> > ahead and make the issue fully public.  (On a related note, I hate it
> > when an issue is sort of "semi-public".  It's the worst possible case.
> > When this happens, it's a reason to opt for a shorter embargo period, or
> > for none at all indeed.)  If an embargo is requested, please make sure
> > there's an exact date and time for the planned public disclosure.
> 
> So far no distro has expressed any interest in having this embargoed,
> and no specific coordinated disclosure date has been proposed by anyone.
> Tim, please make the issue public now by posting it in here.  Thanks!
> 
> Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.