Re: Unreported vulnerability published in media - Promo needs info for response
David Faure <[email protected]>
| Newsgroups | gmane.comp.kde.events |
|---|---|
| Organization | KDE |
| Message-ID | <22049567.ouqheUzb2q__14124.6957051166$1565109877$gmane$org@asterixp50> |
I just told him the same, and he just replied "I can assure you in the future I will follow a more responsible disclosure practice. That's a mistake on my part." Cheers, David. On mardi 6 août 2019 18:40:50 CEST David Cahalane wrote: > Thanks for doing the best you can in this situation. The way Penner's chosen > to go about this is rather annoying. And the timing of when Penner informed > you is good to know for media relations purposes. Some might need a gentle > reminder that you do indeed have day jobs. > > David C. > > Aug 6, 2019, 12:29 PM by [email protected]: > > It's simple: we're working on the fix. > > > > Penner sent us the vulnerability 7 hours ago, probably tired of everyone > > (correctly) telling him to do that rather than what he did (publish a > > vulnerability without telling us!). > > > > 7 hours ago, and we have day jobs, we can't have a full fix or advisory > > yet. > > > > David. > > > > On mardi 6 août 2019 17:53:19 CEST David Cahalane wrote: > >> Hi, > >> > >> The KDE Promo team needs your help on formulating a response to a > >> previously unreported Plasma vulnerability which was published on > >> Twitter and is now making its way through tech media. > >> > >> The technical write-up on the vulnerability can be found here: > >> > >> https://gist.githubusercontent.com/zeropwn/630832df151029cb8f22d5b6b9efae > >> fb/ > >> raw/64aa3d30279acb207f787ce9c135eefd5e52643b/kde-kdesktopfile-command-in > >> ject ion.txt > >> <https://gist.githubusercontent.com/zeropwn/630832df151029cb8f22d5b6b9efa > >> ef > >> b/raw/64aa3d30279acb207f787ce9c135eefd5e52643b/kde-kdesktopfile-command-i > >> nje ction.txt> > >> > >> > >> The author of the ZDnet article claims to have reached out to two KDE > >> members and received no reply. We'd like to get out in front of this with > >> a > >> clear message from KDE. The full article in question can be found here: > >> > >> https://www.zdnet.com/article/unpatched-kde-vulnerability-disclosed-on-tw > >> itt er/ > >> <https://www.zdnet.com/article/unpatched-kde-vulnerability-disclosed-on-t > >> wi > >> tter/> > >> > >> This is obviously a time-sensitive situation, so please get in touch > >> soon. > >> You may want to CC [email protected] <mailto:[email protected]> so we're > >> all on the same page. > >> > >> Thanks, > >> David -- David Faure, [email protected], http://www.davidfaure.fr Working on KDE Frameworks 5