Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <CALPTtNXwk-si9KX9c8dMY2uyKAFdc6NLGPUxrVgXMSCDGQU0xw@mail.gmail.com>
Date: Fri, 10 Jun 2016 09:23:50 +0200
From: Reed Loden <reed@...dloden.com>
To: Sam Saffron <sam.saffron@...il.com>
Cc: oss-security@...ts.openwall.com
Subject: Re: Ruby gem rack-mini-profiler CVE-2016-4442

On Fri, Jun 10, 2016 at 8:10 AM, Sam Saffron <sam.saffron@...il.com> wrote:

>
> I am not sure how to go about announcing this CVE, where else to I
> need to post this?
>

This is actually somewhat documented, believe it or not!

http://guides.rubygems.org/security/#reporting-security-vulnerabilities

Yay for documentation! Though, boo for it needing to be updated since OSVDB
is gone now. :(

~reed

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.