From: Daniel Stenberg Date: Thu, 21 Jul 2016 23:47:13 +0000 (+0200) Subject: SECURITY: mention how to get windows-specific CVEs X-Git-Tag: curl-7_50_1~25 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=c7468e8ea2eeac748bb1f3d1410d2de55e9b5802;p=thirdparty%2Fcurl.git SECURITY: mention how to get windows-specific CVEs ... and make the distros link a proper link --- diff --git a/docs/SECURITY b/docs/SECURITY index 7b245d7bae..3c07e0bbed 100644 --- a/docs/SECURITY +++ b/docs/SECURITY @@ -66,10 +66,13 @@ announcement. workarounds, when the release is out and make sure to credit all contributors properly. -- Request a CVE number from distros@openwall[1] when also informing and - preparing them for the upcoming public security vulnerability announcement - - attach the advisory draft for information. Note that 'distros' won't accept - an embargo longer than 19 days. +- Request a CVE number from + [distros@openwall](http://oss-security.openwall.org/wiki/mailing-lists/distros) + when also informing and preparing them for the upcoming public security + vulnerability announcement - attach the advisory draft for information. Note + that 'distros' won't accept an embargo longer than 19 days and they do not + care for Windows-specific flaws. For windows-specific flaws, request CVE + directly from MITRE. - Update the "security advisory" with the CVE number. @@ -91,7 +94,7 @@ announcement. - The security web page on the web site should get the new vulnerability mentioned. -[1] = http://oss-security.openwall.org/wiki/mailing-lists/distros + CURL-SECURITY (at haxx dot se) ------------------------------