Re: Proper procedure for reporting possible security vulnerabilities?

From: Florian Weimer
Date: Tue Jan 11 2005 - 04:36:01 EST


* Alan Cox:

> vendor-sec@xxxxxx is a cross vendor security list and a good place for
> stuff.

Some people claim that vendor-sec is not trustworthy anymore because
it leaks information, based on the recent forged e-matters advisory.
Personally, I think the intent of the forgers was to discredit
vendor-sec. There's no hard no evidence that there is a systematic
leak (apart from the occasional blunders).
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/