New FreeBSD Security Officer

Arne Wörner arne_woerner at yahoo.com
Thu Sep 29 05:12:28 PDT 2005


--- Juergen Lock <nox at jelal.kn-bremen.de> wrote:
> Btw, should one expect a confirmation email when emailing
> security-officer at FreeBSD.org about a (possibly) new hole?  I'm
> wondering if two mails i sent got lost somehow...
> 
On http://www.freebsd.org./security/ I found the following:
"All FreeBSD Security issues should be reported directly to the
Security Officer Team (mailto:security at FreeBSD.org) personally or
otherwise to the Security Officer
(mailto:security-officer at FreeBSD.org). All reports should at least
contain:

A description of the vulnerability;
What versions of FreeBSD seem to be affected if possible;
Any plausible workaround;
And example code if possible.

After this information has been reported the Security Officer or a
Security Team delegate will get back with you."


This clearly says, that you contacted the right person, and that
somebody should "get back with you"... But it does not say when...
Maybe in a "timely manner"? :-))

I say, have u tried both email addresses (team and the SecOff
himself)?

I say, when did you send those two emails?

-Arne



		
__________________________________ 
Yahoo! Mail - PC Magazine Editors' Choice 2005 
http://mail.yahoo.com


More information about the freebsd-security mailing list