1 |
On Mon, 2007-01-22 at 15:32 -0800, David Herron wrote: |
2 |
> Hi, I just got this and I'm curious how we can be sure these problems |
3 |
> were reported upstream (to Sun)? |
4 |
|
5 |
Pretty sure this was discovered upstream from gentoo, it was just being |
6 |
passed on for those that follow GLSAs. |
7 |
|
8 |
> It doesn't say in this announcement |
9 |
> anything of that sort. |
10 |
|
11 |
Didn't really on the first one I saw about it via CERT. |
12 |
http://www.us-cert.gov/cas/techalerts/TA07-022A.html |
13 |
|
14 |
> Oh, hmm, I was thinking you could have made the |
15 |
> announcement reference pages on bugs.sun.com but I just remembered we |
16 |
> generally don't make visible any security bugs. |
17 |
|
18 |
I would imagine Sun is aware of this on some level or not. I would hope |
19 |
so, usually CERT only does announcements after contacting those |
20 |
responsible/affected. |
21 |
|
22 |
-- |
23 |
William L. Thomson Jr. |
24 |
Gentoo/Java |