[SECURITY] Inquiry about Vulnerability Reporting Process

JustCoding247 <[email protected]> Sun, 22 Jun 2025 22:44:19 +0400
Newsgroups gmane.network.net-snmp.devel
Message-ID <CADtrucFkfJbBeAnXLSxGPkO45mWiFWufAtANJsn+XCHgHAcOiQ@mail.gmail.com>
--===============8631492365115199068==
Content-Type: multipart/alternative; boundary="0000000000004b1a2106382d7c54"

--0000000000004b1a2106382d7c54
Content-Type: text/plain; charset="UTF-8"

Dear Net-SNMP Developers,

I hope this email finds you well.

I am writing to inquire about the proper procedure for reporting a
potential security vulnerability I have discovered in Net-SNMP.

While analyzing the Net-SNMP source code, I have identified what appears to
be a buffer overflow vulnerability in the network statistics functionality.
To follow responsible disclosure practices, I would like to report this
issue privately to the project maintainers before any public disclosure.

Could you please advise on the preferred method for submitting detailed
vulnerability reports? Specifically, I would like to know:

1. Is there a dedicated security contact email or private reporting channel?
2. What information should be included in the vulnerability report?
3. What is the typical timeline for security issue resolution?

I can provide:
- Detailed technical analysis of the vulnerability
- Affected code locations and line numbers
- Potential impact assessment
- Suggested fix/patch recommendations
- Proof-of-concept code (if needed)

I understand the importance of responsible disclosure and am committed to
working with the project team to address this issue appropriately.

Thank you for your time and guidance. I look forward to your response.

Best regards,
JustCoding247

--0000000000004b1a2106382d7c54
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div>Dear Net-SNMP Developers,<br><br>I hope this email finds you well.<br>=
<br>I am writing to inquire about the proper procedure for reporting a pote=
ntial security vulnerability I have discovered in Net-SNMP.<br><br>While an=
alyzing the Net-SNMP source code, I have identified what appears to be a bu=
ffer overflow vulnerability in the network statistics functionality. To fol=
low responsible disclosure practices, I would like to report this issue pri=
vately to the project maintainers before any public disclosure.<br><br>Coul=
d you please advise on the preferred method for submitting detailed vulnera=
bility reports? Specifically, I would like to know:<br><br>1. Is there a de=
dicated security contact email or private reporting channel?<br>2. What inf=
ormation should be included in the vulnerability report?<br>3. What is the =
typical timeline for security issue resolution?<br><br>I can provide:<br>- =
Detailed technical analysis of the vulnerability<br>- Affected code locatio=
ns and line numbers<br>- Potential impact assessment<br>- Suggested fix/pat=
ch recommendations<br>- Proof-of-concept code (if needed)<br><br>I understa=
nd the importance of responsible disclosure and am committed to working wit=
h the project team to address this issue appropriately.<br><br>Thank you fo=
r your time and guidance. I look forward to your response.<br><br>Best rega=
rds,<br>JustCoding247</div>

--0000000000004b1a2106382d7c54--


--===============8631492365115199068==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============8631492365115199068==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Net-snmp-coders mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/net-snmp-coders

--===============8631492365115199068==--