|
|
Subscribe / Log in / New account

A Stack Clash disclosure post-mortem

A Stack Clash disclosure post-mortem

[Security] Posted Jun 21, 2017 18:56 UTC (Wed) by corbet

For those who are curious about how the community deals with a serious vulnerability, Solar Designer's description of the embargo process around the "Stack Clash" issue (and his unhappiness with it) is worth a read. "Qualys first informed the distros list about this upcoming set of issues on May 3. This initial notification didn't say Stack Clash nor anything like that, but merely expressed intent to disclose the issues and concern that the list's maximum embargo duration of 14 to 19 days might not be sufficient in this case. In the resulting discussion, I agreed to consider extending the embargo beyond list policy should there be convincing reasons for that. In retrospect, I think I shouldn't have agreed to that."

Full Story (comments: 3)


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds