oss-sec mailing list archives

Re: CUPS printing system vulnerabilities


From: Mark Esler <mark.esler () canonical com>
Date: Thu, 26 Sep 2024 17:23:24 -0700

On Fri, Sep 27, 2024 at 01:49:52AM +0200, Solar Designer wrote:
Thanks Alan!  On Twitter, Alan further clarified that "once it was clear
the info was out there, the distro makers wanted to end the embargo so
they could publish advisories telling users to disable cups-browsed
instead of waiting for patches to be available - those with VINCE access
had hours of prior notice, not just two."

I don't believe this is how distro security teams saw it. Once a
vulnerability is leaked embargo no longer exists. In this case, the
original disclosure report was fully leaked online. Since the embargo
was broken and PoCs were posted, certainly nobody would want the
originally agreed to coordinated release date (CRD) of October 6th to be
kept. The intention of holding to a same day CRD (20:00 UTC) was to
stage the available patches for release and limit impact.

Attachment: signature.asc
Description:


Current thread: