Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Qualys found some exploits, told parties responsible for fixing the problems, those parties fixed the problems.

These are remarkable because they are conceptually straightforward but the power of the exploits was potentially substantial.

edit: original first sentence was "told Red Hat, Red Hat fixed them." Apparently that was wrong and people (appropriately!) want credit attributed to the right parties.



Actually no, Qualys told Red Hat and SUSE initially (I asked for early access to confirm how bad it was, Red Hat and SUSE are capable of handling very sensitive embargoed material as we have enough engineers internally to do Kernel/glibc/etc stuff in house) and then we (Red Hat and SUSE) agreed that 1) this was as bad as Qualys said and 2) we need to get the entire community involved ASAP (via the distros list and CC's for people not on it like the Kernel people and so on).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: