You are not logged in.
Hi all
I've found a vulnerable default configuration in a package with which privilege escalation is possible. Since I don't want to open a public Gitlab issue, I sent an email to security@archlinux.org a few days ago. However, I have not yet received an answer.
How should I proceed?
Last edited by dcy3rka (2024-02-29 08:34:25)
Offline
In the light of responsible disclosure, you took the right approach. I'd give the team at least one week to respond.
After that you can open an issue on the GitLab bug tracker.
Chances are that if the team does not deem it necessary to react after one week time, either
a) the issue isn't really that bad or
b) nobody's home and other bug-wrangling personnell should be informed that way.
I'd still refrain from publishing too much details if it's really that bad. I.e. I would not publish a POC right away.
Last edited by schard (2024-02-29 08:27:39)
Inofficial first vice president of the Rust Evangelism Strike Force
Offline
Ok, thanks. I will wait another few days. I thought, maybe it was the wrong way or at least a better way exists.
I close this issue for the moment.
Offline
You can create a confidential issue on the Arch gitlab instance which will only be visible to team members with at least Reporter access. You can view such access on the project member's tab (random package selected an example).
Offline
Mod note: moving to Arch Discussion.
Sakura:-
Mobo: MSI MAG X570S TORPEDO MAX // Processor: AMD Ryzen 9 5950X @4.9GHz // GFX: AMD Radeon RX 5700 XT // RAM: 32GB (4x 8GB) Corsair DDR4 (@ 3000MHz) // Storage: 1x 3TB HDD, 6x 1TB SSD, 2x 120GB SSD, 1x 275GB M2 SSD
Making lemonade from lemons since 2015.
Online