Re: Unreported vulnerability published in media - Promo needs info for response

David Faure <[email protected]>
Newsgroups gmane.comp.kde.events
Organization KDE
Message-ID <22049567.ouqheUzb2q__14124.6957051166$1565109877$gmane$org@asterixp50>
I just told him the same, and he just replied

"I can assure you in the future I will follow a more responsible disclosure
practice. That's a mistake on my part."

Cheers,
David.

On mardi 6 août 2019 18:40:50 CEST David Cahalane wrote:
> Thanks for doing the best you can in this situation. The way Penner's chosen
> to go about this is rather annoying. And the timing of when Penner informed
> you is good to know for media relations purposes. Some might need a gentle
> reminder that you do indeed have day jobs.
> 
> David C.
> 
> Aug 6, 2019, 12:29 PM by [email protected]:
> > It's simple: we're working on the fix.
> > 
> > Penner sent us the vulnerability 7 hours ago, probably tired of everyone
> > (correctly) telling him to do that rather than what he did (publish a
> > vulnerability without telling us!).
> > 
> > 7 hours ago, and we have day jobs, we can't have a full fix or advisory
> > yet.
> > 
> > David.
> > 
> > On mardi 6 août 2019 17:53:19 CEST David Cahalane wrote:
> >> Hi,
> >> 
> >> The KDE Promo team needs your help on formulating a response to a
> >> previously unreported Plasma vulnerability which was published on
> >> Twitter and is now making its way through tech media.
> >> 
> >> The technical write-up on the vulnerability can be found here:
> >> 
> >> https://gist.githubusercontent.com/zeropwn/630832df151029cb8f22d5b6b9efae
> >> fb/
> >> raw/64aa3d30279acb207f787ce9c135eefd5e52643b/kde-kdesktopfile-command-in
> >> ject ion.txt
> >> <https://gist.githubusercontent.com/zeropwn/630832df151029cb8f22d5b6b9efa
> >> ef
> >> b/raw/64aa3d30279acb207f787ce9c135eefd5e52643b/kde-kdesktopfile-command-i
> >> nje ction.txt>
> >> 
> >> 
> >> The author of the ZDnet article claims to have reached out to two KDE
> >> members and received no reply. We'd like to get out in front of this with
> >> a
> >> clear message from KDE. The full article in question can be found here:
> >> 
> >> https://www.zdnet.com/article/unpatched-kde-vulnerability-disclosed-on-tw
> >> itt er/
> >> <https://www.zdnet.com/article/unpatched-kde-vulnerability-disclosed-on-t
> >> wi
> >> tter/>
> >> 
> >> This is obviously a time-sensitive situation, so please get in touch
> >> soon.
> >> You may want to CC [email protected] <mailto:[email protected]> so we're
> >> all on the same page.
> >> 
> >> Thanks,
> >> David


-- 
David Faure, [email protected], http://www.davidfaure.fr
Working on KDE Frameworks 5
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.