
oss-sec mailing list archives
Re: CUPS printing system vulnerabilities
From: Mark Esler <mark.esler () canonical com>
Date: Thu, 26 Sep 2024 17:23:24 -0700
On Fri, Sep 27, 2024 at 01:49:52AM +0200, Solar Designer wrote:
Thanks Alan! On Twitter, Alan further clarified that "once it was clear the info was out there, the distro makers wanted to end the embargo so they could publish advisories telling users to disable cups-browsed instead of waiting for patches to be available - those with VINCE access had hours of prior notice, not just two."
I don't believe this is how distro security teams saw it. Once a vulnerability is leaked embargo no longer exists. In this case, the original disclosure report was fully leaked online. Since the embargo was broken and PoCs were posted, certainly nobody would want the originally agreed to coordinated release date (CRD) of October 6th to be kept. The intention of holding to a same day CRD (20:00 UTC) was to stage the available patches for release and limit impact.
Attachment:
signature.asc
Description:
Current thread:
- CUPS printing system vulnerabilities Solar Designer (Sep 26)
- Re: CUPS printing system vulnerabilities Alan Coopersmith (Sep 26)
- Re: CUPS printing system vulnerabilities Solar Designer (Sep 26)
- Re: CUPS printing system vulnerabilities Zdenek Dohnal (Sep 26)
- Re: CUPS printing system vulnerabilities Michael Sweet (Sep 26)
- Re: CUPS printing system vulnerabilities Mark Esler (Sep 26)
- Re: CUPS printing system vulnerabilities Solar Designer (Sep 26)
- Re: CUPS printing system vulnerabilities Alan Coopersmith (Sep 26)
- Re: CUPS printing system vulnerabilities Will Dormann (Sep 27)