Gentoo Archives: gentoo-security

From: Kurt Lieber <klieber@g.o>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Gentoo Linux Vulnerability Treatment Policy
Date: Tue, 18 May 2004 21:20:00
Message-Id: 20040518212036.GK26130@mail.lieber.org
In Reply to: Re: [gentoo-security] Gentoo Linux Vulnerability Treatment Policy by Tobias Weisserth
1 On Tue, May 18, 2004 at 11:07:22PM +0200 or thereabouts, Tobias Weisserth wrote:
2 > "Confidential vulnerabilities
3 >
4 > Confidential vulnerabilities (for example coming from developer's direct
5 > communication or restricted vendor-sec lists) should follow a specific
6 > procedure. They should not appear as a public bugzilla entry, but only
7 > in the (private) GLSAMaker tool. They should get corrected using private
8 > communication channels between the GLSA coordinator and the package
9 > maintainer."
10 >
11 > What's this about? I can't imagine what a "confidential vulnerability"
12 > might be. This immediately prompts for "security by obscurity" remark,
13 > don't you think?
14
15 It means that if a vendor contacts us to notify us of a security
16 vulnerability in their product, but asks us to keep it confidential until a
17 pre-defined release date, we will respect their wishes and treat the bug as
18 confidential.
19
20 --kurt

Replies

Subject Author
Re: [gentoo-security] Gentoo Linux Vulnerability Treatment Policy Tobias Weisserth <tobias@×××××××××.de>