Upcoming OpenSSH vulnerability
Posted Jun 25, 2002 8:33 UTC (Tue) by
garloff (subscriber, #319)
Parent article:
Upcoming OpenSSH vulnerability
This statement from Theo really makes one wonder what's going on.
If a vulnerability is found in a software package, what the one who
discovers should do is to contact the authors of the software.
This apparently happened in this case. The next step for the authors
is to fix the problem and contact distributors. There are mailing
lists to coordinate these efforts. A few days later, most distributors
should have fixes ready and the disclosure of the vulnerability can
happen and all distros can send their sec announcements within a short
amount of time.
For some reason Theo seems to imply he does not want to follow this
procedure. Instead he wants that the distributors implement a workaround
beforehand. Strange way of dealing!
After reading about the Privilege Separation stuff it sounds like a very
good idea to me. After reading Theo's "I want to force it down your
throats" I'm not so sure any more ...
(
Log in to post comments)