[apparmor] private apparmor security bug on public list?

Steve Beattie steve at nxnw.org
Tue Nov 6 20:29:21 UTC 2018


On Tue, Nov 06, 2018 at 01:55:45PM -0600, Tyler Hicks wrote:
> On 2018-11-06 20:48:40, Jann Horn wrote:
> > I'm subscribed to apparmor at lists.ubuntu.com, and I noticed that I got
> > bug mail for https://bugs.launchpad.net/bugs/1800789 via this list
> > when the bug was still marked as a security bug.
> 
> The problem looks to be in the bug subscription configuration for the
> apparmor-profiles project:
> 
>   https://bugs.launchpad.net/apparmor-profiles/+subscriptions
> 
> The ~apparmor-dev team is subscribed which is described here:
> 
>   https://launchpad.net/~apparmor-dev
> 
> You can see that the email address listed is the address for this list.
> 
> It is worth noting that the apparmor project itself does not have this
> problem:
> 
>   https://bugs.launchpad.net/apparmor/+subscriptions

It should be noted that in this instance, the messages around
https://bugs.launchpad.net/bugs/1800789 were held for moderation,
but I mistakenly let them through, not realizing why they had been
held for moderation.

(In this case, it was not a drastic mistake, as
https://gitlab.com/apparmor/apparmor-profiles/issues/3 had already
been filed publicly.)

-- 
Steve Beattie
<sbeattie at ubuntu.com>
http://NxNW.org/~steve/
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <https://lists.ubuntu.com/archives/apparmor/attachments/20181106/ba709397/attachment.sig>


More information about the AppArmor mailing list