Reporting security bug
Brian Murray
brian at ubuntu.com
Wed Nov 4 21:33:42 UTC 2009
On Mon, Nov 02, 2009 at 06:00:06PM -0600, Jonathan Hayward wrote:
> Is there a way, besides Launchpad, to appropriately and privately
> report a possible vulnerability?
It is possible to report private bugs in Launchpad and flag them as a
security issue. This will ensure that the security team sees and
reviews them in a timely fashion.
> I think I tripped on a way for a Jaunty user authorized to install
> updates to execute arbitrary code with root privilege. I'd ideally
> like to report it privately (can I do so on this list)?
No, this list is public.
--
Brian Murray @ubuntu.com
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 197 bytes
Desc: Digital signature
URL: <https://lists.ubuntu.com/archives/ubuntu-bugsquad/attachments/20091104/f9eb6691/attachment.sig>
More information about the Ubuntu-bugsquad
mailing list