[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Xen-devel] Earlier embargoed pre-disclosure without patches



>>> On 22.05.15 at 15:14, <major.hayden@xxxxxxxxxxxxx> wrote:
> My request is that the Xen security team would send a pre-disclosure notice 
> of the vulnerability as soon as permission from the discoverer is granted 
> *even if* patches aren't available.  For example, I'd like to receive a 
> notice saying "there's a vulnerability, here's what we know about it, patches 
> are forthcoming with additional information".

If you were to ask for this only if the time gap until embargo expiry
was less than the default of two weeks, maybe I would buy this.

Jan


_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
http://lists.xen.org/xen-devel


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.