Reporting security bug

Brian Murray brian at ubuntu.com
Wed Nov 4 21:33:42 UTC 2009


On Mon, Nov 02, 2009 at 06:00:06PM -0600, Jonathan Hayward wrote:
> Is there a way, besides Launchpad, to appropriately and privately
> report a possible vulnerability?

It is possible to report private bugs in Launchpad and flag them as a 
security issue.  This will ensure that the security team sees and 
reviews them in a timely fashion.

> I think I tripped on a way for a Jaunty user authorized to install
> updates to execute arbitrary code with root privilege. I'd ideally
> like to report it privately (can I do so on this list)?
 
No, this list is public.

-- 
Brian Murray                                                 @ubuntu.com
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 197 bytes
Desc: Digital signature
URL: <https://lists.ubuntu.com/archives/ubuntu-bugsquad/attachments/20091104/f9eb6691/attachment.sig>


More information about the Ubuntu-bugsquad mailing list