You are not logged in.

#1 2024-02-29 08:17:42

dcy3rka
Member
Registered: 2022-01-19
Posts: 52

[SOLVED] No answer from security@archlinux.org

Hi all

I've found a vulnerable default configuration in a package with which privilege escalation is possible. Since I don't want to open a public Gitlab issue, I sent an email to security@archlinux.org a few days ago. However, I have not yet received an answer.

How should I proceed?

Last edited by dcy3rka (2024-02-29 08:34:25)

Offline

#2 2024-02-29 08:24:30

schard
Forum Moderator
From: Hannover
Registered: 2016-05-06
Posts: 2,111
Website

Re: [SOLVED] No answer from security@archlinux.org

In the light of responsible disclosure, you took the right approach. I'd give the team at least one week to respond.
After that you can open an issue on the GitLab bug tracker.
Chances are that if the team does not deem it necessary to react after one week time, either
a) the issue isn't really that bad or
b) nobody's home and other bug-wrangling personnell should be informed that way.
I'd still refrain from publishing too much details if it's really that bad. I.e. I would not publish a POC right away.

Last edited by schard (2024-02-29 08:27:39)


Inofficial first vice president of the Rust Evangelism Strike Force

Offline

#3 2024-02-29 08:34:11

dcy3rka
Member
Registered: 2022-01-19
Posts: 52

Re: [SOLVED] No answer from security@archlinux.org

Ok, thanks. I will wait another few days. I thought, maybe it was the wrong way or at least a better way exists.

I close this issue for the moment.

Offline

#4 2024-02-29 09:08:51

loqs
Member
Registered: 2014-03-06
Posts: 18,034

Re: [SOLVED] No answer from security@archlinux.org

You can create a confidential issue on the Arch gitlab instance which will only be visible to team members with at least Reporter access.  You can view such access on the project member's tab (random package selected an example).

Offline

#5 2024-02-29 10:51:22

WorMzy
Administrator
From: Scotland
Registered: 2010-06-16
Posts: 12,399
Website

Re: [SOLVED] No answer from security@archlinux.org

Mod note: moving to Arch Discussion.


Sakura:-
Mobo: MSI MAG X570S TORPEDO MAX // Processor: AMD Ryzen 9 5950X @4.9GHz // GFX: AMD Radeon RX 5700 XT // RAM: 32GB (4x 8GB) Corsair DDR4 (@ 3000MHz) // Storage: 1x 3TB HDD, 6x 1TB SSD, 2x 120GB SSD, 1x 275GB M2 SSD

Making lemonade from lemons since 2015.

Online

Board footer

Powered by FluxBB