|
Message-ID: <20150223154726.GA22383@videolan.org> Date: Mon, 23 Feb 2015 16:47:26 +0100 From: Jean-Baptiste Kempf <jb@...eolan.org> To: Kurt Seifried <kseifried@...hat.com> Cc: oss-security@...ts.openwall.com, Assign a CVE Identifier <cve-assign@...re.org> Subject: Re: [videolan] older issues in libbluray On 23 Feb, Kurt Seifried wrote : > Again my apologies for this mess. The good news is that all our current > embargoed flaws (none against VLC currently =) are being actively > handled (e.g. worked on in a current time frame) and moving forwards we > should hopefully be able to avoid issues like this. One libbluray issue was already fixed. The second one is not really fixable, since BD-J is actually executing java code from the outside. > Also one request (not just specific to VLC, but everyone with a > project): please have a security@ email address for your project or a > security web page that makes it obvious how to contact and report things We have a security email. With my kindest regards, -- Jean-Baptiste Kempf http://www.jbkempf.com/ - +33 672 704 734 Sent from my Electronic Device
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.