From mboxrd@z Thu Jan 1 00:00:00 1970 From: ludo@gnu.org (Ludovic =?utf-8?Q?Court=C3=A8s?=) Subject: Re: Dealing with CVEs that apply to unspecified package versions Date: Thu, 16 Mar 2017 11:07:55 +0100 Message-ID: <8760j91qmc.fsf@gnu.org> References: <877f4284un.fsf@gnu.org> <20170311040534.GA31017@jasmine> <87bmt89ij7.fsf@gnu.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:36948) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1coSK9-00006E-22 for guix-devel@gnu.org; Thu, 16 Mar 2017 06:08:02 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1coSK5-0003w5-Uc for guix-devel@gnu.org; Thu, 16 Mar 2017 06:08:01 -0400 Received: from fencepost.gnu.org ([2001:4830:134:3::e]:40695) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1coSK5-0003vz-Qr for guix-devel@gnu.org; Thu, 16 Mar 2017 06:07:57 -0400 Received: from [193.50.110.167] (port=55642 helo=ribbon) by fencepost.gnu.org with esmtpsa (TLS1.2:RSA_AES_256_CBC_SHA1:256) (Exim 4.82) (envelope-from ) id 1coSK5-0001iB-A1 for guix-devel@gnu.org; Thu, 16 Mar 2017 06:07:57 -0400 In-Reply-To: <87bmt89ij7.fsf@gnu.org> ("Ludovic \=\?utf-8\?Q\?Court\=C3\=A8s\=22'\?\= \=\?utf-8\?Q\?s\?\= message of "Sat, 11 Mar 2017 12:09:32 +0100") List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel ludo@gnu.org (Ludovic Court=C3=A8s) skribis: > What about raising the issue on oss-sec? Ideally the QEMU folks would > take care of labeling QEMU=E2=80=99s CVEs, the libxml2 folks would take c= are of > theirs, etc. For the record I followed up on this discussion on oss-sec: http://www.openwall.com/lists/oss-security/2017/03/15/3 Ludo=E2=80=99.