You are not logged in.

#1 2024-02-29 08:17:42

dcy3rka
Member
Registered: 2022-01-19
Posts: 52

[SOLVED] No answer from security@archlinux.org

Hi all

I've found a vulnerable default configuration in a package with which privilege escalation is possible. Since I don't want to open a public Gitlab issue, I sent an email to security@archlinux.org a few days ago. However, I have not yet received an answer.

How should I proceed?

Last edited by dcy3rka (2024-02-29 08:34:25)

Offline

#2 2024-02-29 08:24:30

schard
Forum Moderator
From: Hannover
Registered: 2016-05-06
Posts: 1,992
Website

Re: [SOLVED] No answer from security@archlinux.org

In the light of responsible disclosure, you took the right approach. I'd give the team at least one week to respond.
After that you can open an issue on the GitLab bug tracker.
Chances are that if the team does not deem it necessary to react after one week time, either
a) the issue isn't really that bad or
b) nobody's home and other bug-wrangling personnell should be informed that way.
I'd still refrain from publishing too much details if it's really that bad. I.e. I would not publish a POC right away.

Last edited by schard (2024-02-29 08:27:39)


macro_rules! yolo { { $($tokens:tt)* } => { unsafe { $($tokens)* } }; }

Offline

#3 2024-02-29 08:34:11

dcy3rka
Member
Registered: 2022-01-19
Posts: 52

Re: [SOLVED] No answer from security@archlinux.org

Ok, thanks. I will wait another few days. I thought, maybe it was the wrong way or at least a better way exists.

I close this issue for the moment.

Offline

#4 2024-02-29 09:08:51

loqs
Member
Registered: 2014-03-06
Posts: 17,469

Re: [SOLVED] No answer from security@archlinux.org

You can create a confidential issue on the Arch gitlab instance which will only be visible to team members with at least Reporter access.  You can view such access on the project member's tab (random package selected an example).

Offline

#5 2024-02-29 10:51:22

WorMzy
Forum Moderator
From: Scotland
Registered: 2010-06-16
Posts: 11,907
Website

Re: [SOLVED] No answer from security@archlinux.org

Mod note: moving to Arch Discussion.


Sakura:-
Mobo: MSI MAG X570S TORPEDO MAX // Processor: AMD Ryzen 9 5950X @4.9GHz // GFX: AMD Radeon RX 5700 XT // RAM: 32GB (4x 8GB) Corsair DDR4 (@ 3000MHz) // Storage: 1x 3TB HDD, 6x 1TB SSD, 2x 120GB SSD, 1x 275GB M2 SSD

Making lemonade from lemons since 2015.

Offline

Board footer

Powered by FluxBB