1 |
On Tue, May 18, 2004 at 11:07:22PM +0200 or thereabouts, Tobias Weisserth wrote: |
2 |
> "Confidential vulnerabilities |
3 |
> |
4 |
> Confidential vulnerabilities (for example coming from developer's direct |
5 |
> communication or restricted vendor-sec lists) should follow a specific |
6 |
> procedure. They should not appear as a public bugzilla entry, but only |
7 |
> in the (private) GLSAMaker tool. They should get corrected using private |
8 |
> communication channels between the GLSA coordinator and the package |
9 |
> maintainer." |
10 |
> |
11 |
> What's this about? I can't imagine what a "confidential vulnerability" |
12 |
> might be. This immediately prompts for "security by obscurity" remark, |
13 |
> don't you think? |
14 |
|
15 |
It means that if a vendor contacts us to notify us of a security |
16 |
vulnerability in their product, but asks us to keep it confidential until a |
17 |
pre-defined release date, we will respect their wishes and treat the bug as |
18 |
confidential. |
19 |
|
20 |
--kurt |