Very serious security problem
"John Haugeland" <[email protected]>
| Newsgroups | gmane.comp.web.html-tidy.user |
|---|---|
| Message-ID | <[email protected]> |
We have become aware of a very serious XSS injection in HTML Tidy (several weeks late because securityfocus does not report defects to vendors, which is a significant problem of its own right.) I am prepared to provide a trivial patch to close it. What is the appropriate process for reporting security defects in private, to allow the patch cycle to close the problem without aggravating it?