This is the mail archive of the libc-alpha@sourceware.org mailing list for the glibc project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

Re: Streamlining CVE assignment for glibc


On 10/02/2015 08:29 PM, Roland McGrath wrote:
> Just make sure it explains everything about CVEs and our processes related
> to them that glibc hackers might need to know.

If you don't care for CVE for other reasons, you can ignore it.

As far as the security process is concerned, *please* mark security bugs
as security+ in Bugzilla.  Similarly, when reviewing patches and you
think you are looking at a bug fix which addresses a security
vulnerability without being recognized as such, please speak up.

A significant fraction of important security bugs started as
non-security bugs and were recognized as security-relevant only after
fixing them.  Which is both a good (we are fixing relevant bugs) and bad
(downstreams will miss opportunities to bundle security fixes with other
changes).

Florian


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]