<div dir="ltr"><div class="gmail_quote gmail_quote_container"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><p style="box-sizing:border-box;margin:0px;color:rgb(13,13,13);font-family:-apple-system-body,ui-sans-serif,-apple-system,"system-ui","Segoe UI",Helvetica,"Apple Color Emoji",Arial,"sans-serif","Segoe UI Emoji","Segoe UI Symbol";font-size:16px">Hello,</p><p style="box-sizing:border-box;margin:0px;color:rgb(13,13,13);font-family:-apple-system-body,ui-sans-serif,-apple-system,"system-ui","Segoe UI",Helvetica,"Apple Color Emoji",Arial,"sans-serif","Segoe UI Emoji","Segoe UI Symbol";font-size:16px">I’m following up regarding the security vulnerability I reported in GNU Binutils 2.47 affecting <code style="box-sizing:border-box;font-family:-apple-system-body,ui-sans-serif,-apple-system,"system-ui","Segoe UI",Helvetica,"Apple Color Emoji",Arial,"sans-serif","Segoe UI Emoji","Segoe UI Symbol";font-size:inherit;overflow-x:auto;border-radius:4px;background-image:none;background-position:0% 0%;background-size:auto;background-repeat:repeat;background-origin:padding-box;background-clip:border-box;padding:0.15rem 0.3rem">objcopy</code>.</p><p style="box-sizing:border-box;margin:0px;color:rgb(13,13,13);font-family:-apple-system-body,ui-sans-serif,-apple-system,"system-ui","Segoe UI",Helvetica,"Apple Color Emoji",Arial,"sans-serif","Segoe UI Emoji","Segoe UI Symbol";font-size:16px">Thank you for reviewing and addressing the issue.</p><p style="box-sizing:border-box;margin:0px;color:rgb(13,13,13);font-family:-apple-system-body,ui-sans-serif,-apple-system,"system-ui","Segoe UI",Helvetica,"Apple Color Emoji",Arial,"sans-serif","Segoe UI Emoji","Segoe UI Symbol";font-size:16px">I wanted to ask about the next steps in the vulnerability disclosure process. In particular:</p><ul style="box-sizing:border-box;margin:0px;list-style-type:"\002022 ";color:rgb(13,13,13);font-family:-apple-system-body,ui-sans-serif,-apple-system,"system-ui","Segoe UI",Helvetica,"Apple Color Emoji",Arial,"sans-serif","Segoe UI Emoji","Segoe UI Symbol";font-size:16px"><li style="box-sizing:border-box">Is the issue expected to receive a CVE identifier?</li><li style="box-sizing:border-box">Is there an expected timeline for the fix/release and public disclosure?</li><li style="box-sizing:border-box">Does the Binutils project offer any financial reward or bounty for responsibly reported security vulnerabilities?</li></ul><p style="box-sizing:border-box;margin:0px;color:rgb(13,13,13);font-family:-apple-system-body,ui-sans-serif,-apple-system,"system-ui","Segoe UI",Helvetica,"Apple Color Emoji",Arial,"sans-serif","Segoe UI Emoji","Segoe UI Symbol";font-size:16px">Thank you again for your time and for looking into the report.</p><p style="box-sizing:border-box;margin:0px;color:rgb(13,13,13);font-family:-apple-system-body,ui-sans-serif,-apple-system,"system-ui","Segoe UI",Helvetica,"Apple Color Emoji",Arial,"sans-serif","Segoe UI Emoji","Segoe UI Symbol";font-size:16px">Best regards,<br style="box-sizing:border-box">Mostafa</p>
</blockquote></div></div>