Policy for posting security bug reports?

Florian Weimer fw@deneb.enyo.de
Mon Jun 25 17:26:00 GMT 2012


* Paul Eggert:

> People are also welcome to report bugs via more-formal
> approaches, e.g., the U.S. Computer Emergency Readiness Team
> <http://www.kb.cert.org/vuls/html/report-a-vulnerability/>.
> There is a formal channel between US-CERT and the GNU C
> library developers.  It used to see some activity, but
> the hotline hasn't rung for quite some time, presumably
> since nothing has been important enough.

Please note that notifying CERT/CC does not always ensure that
affected distributions are notified.  So you'd have to do that anyway,
just to be on the safe side.

Alternatively, you could ask any of the distributions with a security
team for assistance, and they will make sure that other distributions
are informed, assign a CVE name, negotiate a coordinated disclosure
date, help with testing, etc.



More information about the Libc-alpha mailing list