Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 12 Apr 2021 12:21:34 +0200
From:      Miroslav Lachman <000.fbsd@quip.cz>
To:        Gian Piero Carrubba <gpiero@rm-rf.it>, freebsd-security@freebsd.org
Subject:   Re: FreeBSD Security Advisory FreeBSD-SA-21:08.vm missing in vuxml
Message-ID:  <d7cee6e3-f209-3bdd-8df4-7429243d5fe1@quip.cz>
In-Reply-To: <20210411194932.t4a6dtjdvhynj2uf@robinhood.fdc.rm-rf.it>
References:  <20210406202258.1642E15C4A@freefall.freebsd.org> <20210406202303.3B6F715D1E@freefall.freebsd.org> <20210406202309.EECD015EA7@freefall.freebsd.org> <20210411075824.fzrbnrtus6iiw2cq@robinhood.fdc.rm-rf.it> <20210411192125.knknarbiul3alggx@robinhood.fdc.rm-rf.it> <ab68d1d4-5ba3-3e94-b381-3b6d86516796@quip.cz> <20210411194932.t4a6dtjdvhynj2uf@robinhood.fdc.rm-rf.it>

next in thread | previous in thread | raw e-mail | index | archive | help
On 11/04/2021 21:49, Gian Piero Carrubba wrote:
> * [Sun, Apr 11, 2021 at 09:36:05PM +0200] Miroslav Lachman:
>> On 11/04/2021 21:21, Gian Piero Carrubba wrote:
>>> CCing ports-secteam@ as it seems a more appropriate recipient.
>>
>> Vulnerabilities in base should be handled by core secteam, not ports 
>> secteam.
> 
> The maintainer address for vuxml is ports-secteam@, so my impression is 
> that entries in vuxml, regardless if they affect base or ports, are 
> managed by them. Am I wrong?

Because there are entries mainly for ports and vuxml is port too. But 
the responsible side for vulnerabilities in base is Security Officer 
Team. They are publishing SAs, they should create and submit entries to 
vuxml. They are almost always lacking behind, sometimes for months. I 
tried created patches with entries in the past because I am the author 
of base-audit script and maintainer of the port but then it was waiting 
for a long time to have it confirmed by Security Officer Team.

I fought with this many times.

Responsibilities of the FreeBSD Ports Security Team
https://wiki.freebsd.org/ports-secteam

Kind regards
Miroslav Lachman



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?d7cee6e3-f209-3bdd-8df4-7429243d5fe1>