Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <110f8440-7612-6014-fd40-2f8c72097b9a@catalyst.net.nz>
Date: Wed, 24 Jul 2019 09:55:13 +1200
From: Douglas Bagnall <douglas.bagnall@...alyst.net.nz>
To: oss-security@...ts.openwall.com
Cc: abartlet@...ba.org
Subject: Security release pre-announcement messages

On 22/07/19 11:50 PM, Solar Designer wrote:
> Exactly.  It's just an unusual disclosure process that involves giving
> the users a heads-up a few days before public disclosure of the actual
> vulnerabilities and fixes.  So far, this process is practiced by OpenSSL
> and Exim (any others?)
> 

On the Samba team we use wording like this:

https://lists.samba.org/archive/samba/2019-June/223621.html

----------------------------
Subject: Heads-up: Security Releases ahead!

Hi,

This is a heads-up that there will be Samba security updates on
Wednesday, June 19 2019. Please make sure that your Samba
servers will be updated soon after the release!

Impacted components:
 - AD DC (CVSS 6.5, Medium)
-----------------------------

We now do this systematically, after a haphazard start.

To help ourselves stay on track, we are trying to formalise our
process into something approaching a checklist:

https://wiki.samba.org/index.php/Samba_Security_Process

and we are happy to hear suggestions for improvement.

cheers,
Douglas

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.