[SECURITY] Inquiry about Vulnerability Reporting Process
JustCoding247 <[email protected]> Sun, 22 Jun 2025 22:44:19 +0400
| Newsgroups | gmane.network.net-snmp.devel |
|---|---|
| Message-ID | <CADtrucFkfJbBeAnXLSxGPkO45mWiFWufAtANJsn+XCHgHAcOiQ@mail.gmail.com> |
--===============8631492365115199068== Content-Type: multipart/alternative; boundary="0000000000004b1a2106382d7c54" --0000000000004b1a2106382d7c54 Content-Type: text/plain; charset="UTF-8" Dear Net-SNMP Developers, I hope this email finds you well. I am writing to inquire about the proper procedure for reporting a potential security vulnerability I have discovered in Net-SNMP. While analyzing the Net-SNMP source code, I have identified what appears to be a buffer overflow vulnerability in the network statistics functionality. To follow responsible disclosure practices, I would like to report this issue privately to the project maintainers before any public disclosure. Could you please advise on the preferred method for submitting detailed vulnerability reports? Specifically, I would like to know: 1. Is there a dedicated security contact email or private reporting channel? 2. What information should be included in the vulnerability report? 3. What is the typical timeline for security issue resolution? I can provide: - Detailed technical analysis of the vulnerability - Affected code locations and line numbers - Potential impact assessment - Suggested fix/patch recommendations - Proof-of-concept code (if needed) I understand the importance of responsible disclosure and am committed to working with the project team to address this issue appropriately. Thank you for your time and guidance. I look forward to your response. Best regards, JustCoding247 --0000000000004b1a2106382d7c54 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div>Dear Net-SNMP Developers,<br><br>I hope this email finds you well.<br>= <br>I am writing to inquire about the proper procedure for reporting a pote= ntial security vulnerability I have discovered in Net-SNMP.<br><br>While an= alyzing the Net-SNMP source code, I have identified what appears to be a bu= ffer overflow vulnerability in the network statistics functionality. To fol= low responsible disclosure practices, I would like to report this issue pri= vately to the project maintainers before any public disclosure.<br><br>Coul= d you please advise on the preferred method for submitting detailed vulnera= bility reports? Specifically, I would like to know:<br><br>1. Is there a de= dicated security contact email or private reporting channel?<br>2. What inf= ormation should be included in the vulnerability report?<br>3. What is the = typical timeline for security issue resolution?<br><br>I can provide:<br>- = Detailed technical analysis of the vulnerability<br>- Affected code locatio= ns and line numbers<br>- Potential impact assessment<br>- Suggested fix/pat= ch recommendations<br>- Proof-of-concept code (if needed)<br><br>I understa= nd the importance of responsible disclosure and am committed to working wit= h the project team to address this issue appropriately.<br><br>Thank you fo= r your time and guidance. I look forward to your response.<br><br>Best rega= rds,<br>JustCoding247</div> --0000000000004b1a2106382d7c54-- --===============8631492365115199068== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============8631492365115199068== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Net-snmp-coders mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/net-snmp-coders --===============8631492365115199068==--