LWN.net Logo

TWiki hole

TWiki hole

Posted Nov 18, 2004 17:27 UTC (Thu) by bronson (subscriber, #4806)
In reply to: TWiki hole by colas
Parent article: freedesktop.org site compromised

Um, it is YOUR obligation to notify your users of security holes using any reasonable means possible, especially if the hole is already in the wild! This includes Bugtraq, your front page, your news section, your mailing lists, notifying all distributions that include your package, etc. Projects that do this well are PHP, Apache, Gallery, ISC software, etc.

At this point, it seems like the TWiki project has some serious damage control to perform. How are you going to assure your users that something like this will not happen again?


(Log in to post comments)

TWiki hole

Posted Nov 25, 2004 17:22 UTC (Thu) by Cato (subscriber, #7643) [Link]

Try searching for CAN-2004-1037 - this will find all the various reports of this vulnerability to a wide range of security email lists, including Bugtraq (most sent on Nov 12th).

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds