From owner-freebsd-security@FreeBSD.ORG Wed Apr 9 18:00:04 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 67FF9B4A for ; Wed, 9 Apr 2014 18:00:04 +0000 (UTC) Received: from mail.rootservice.org (devgate.rootservice.org [144.76.199.8]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 26FFC1901 for ; Wed, 9 Apr 2014 18:00:03 +0000 (UTC) Received: from devnoip.rootservice.org (devnoip.rootservice.org [46.59.210.109]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.rootservice.org (Postfix) with ESMTPSA id 3g3tYX65tqzdG50 for ; Wed, 9 Apr 2014 19:59:59 +0200 (CEST) Date: Wed, 09 Apr 2014 20:00:01 +0200 From: Joe User Organization: RootService MIME-Version: 1.0 To: freebsd-security@freebsd.org Subject: Re: Proposal References: <86txa2z8xl.fsf@nine.des.no> In-Reply-To: <86txa2z8xl.fsf@nine.des.no> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Message-Id: <3g3tYW2jPgz62Y0@devnoip.rootservice.org> X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list Reply-To: joeuser@rootservice.org List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 09 Apr 2014 18:00:04 -0000 On 09.04.2014 19:53, Dag-Erling Smørgrav wrote: > Pawel Biernacki writes: >> RedHat managed to provide the fix within 21 hours but aparently they >> knew very eraly about the issue. FreeBSD Security Team didn't? Why? >> You can _see_ the whole process on their bugzilla >> https://bugzilla.redhat.com/show_bug.cgi?id=1084875. > > No you can't. That ticket is just window dressing. By the time it was > created, RedHat had known about the issue for at least a week, and > probably more. > > DES > According to Kurts Post on oss-sec RedHat didn't know it before others. Regards, Joe User