Its a hard claim to accept that Debian didn't follow good procedure when the bug was reported
in a public forum and existed there for nearly 3 months for all the internet to see. If this
bug was reported via private channels such as vendor-sec and then Debian went about releasing
it to the world anyways, then yes you would be right, but once its out there, its out there.
I'm sorry, but there is no undo on the internet.
Posted Apr 14, 2008 18:02 UTC (Mon) by shane (subscriber, #3335)
[Link]
To be fair, there are a lot of public forums on the Internet. Every distribution has one, and software developers do not have the time to follow every single possible channel for bug reports.
Normal procedure is for distributions to push bug reports and other patches upstream to the main developers. In my experience distributions tend to be pretty bad about this process, and maybe frustration with this has contributed to the asinine actions from the OpenSSH developers.