LWN.net Logo

Releases for recent security vulnerability

From:  Gustavo Narea <me-AT-gustavonarea.net>
To:  python-dev-AT-python.org
Subject:  Releases for recent security vulnerability
Date:  Fri, 15 Apr 2011 09:35:06 +0100
Message-ID:  <BANLkTi=FtJ_oZe-pKnNNANFTDehWrx-J2A@mail.gmail.com>
Archive-link:  Article, Thread

Hi all,

How come a description of how to exploit a security vulnerability
comes before a release for said vulnerability? I'm talking about this:
http://blog.python.org/2011/04/urllib-security-vulnerabil...

My understanding is that the whole point of asking people not to
report security vulnerability publicly was to allow time to release a
fix.

If developers haven't had enough time to release the fix, that's fine.
But I can't think of a sensible reason why it should be announced
first.

Cheers,

 - Gustavo.


(Log in to post comments)

Copyright © 2011, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds