Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <102a76f4-b371-8c54-7dcd-78010b428849@oracle.com>
Date: Mon, 4 Oct 2021 08:48:50 -0700
From: Alan Coopersmith <alan.coopersmith@...cle.com>
To: oss-security@...ts.openwall.com
Subject: Re: 3 new CVE's in vim

On 9/30/2021 7:39 PM, Alan Coopersmith wrote:
> I haven't seen these make it to the list yet, but three CVE's were
> recently assigned for bugs in vim.  [I personally don't see how
> there's a security boundary crossed in normal vim usage here, but
> could see issues if someone had configured vim to run with raised
> privileges for editing system/application configuration files or
> similar.]

I do note all three of these were submitted via huntr.dev, which offers
bounties for both reporting & fixing security bugs.  As a maintainer of
an upstream open source project which is struggling with finding people
to fix reported security bugs [1], I do appreciate the additional
incentive to provide fixes here.  But as a maintainer of a distro, I see
a mismatch with the incentives here, as you get bounties for accepting
everything as a security bug and not pushing back, and flooding the
distros with CVE's - even if your distro policy isn't to handle every
CVE that applies, security auditors will often make your users query
about every CVE that they think applies, costing your time to respond.

[1] https://indico.freedesktop.org/event/1/contributions/28/
https://www.youtube.com/watch?v=IU3NeVvDSp0

-- 
       -Alan Coopersmith-               alan.coopersmith@...cle.com
        Oracle Solaris Engineering - https://blogs.oracle.com/alanc

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.