>> However, the devs actively monitor the queue. See
>> https://www.openssl.org/about/roadmap.html and
>> https://groups.google.com/forum/#!msg/mailing.openssl.users/mDrMrd3zOuQ/BRS_VLZB_mYJ.
>
> That's only useful if a new report finds its way onto the queue.
> Lack of email suggests that this one hasn't, and a search of RT
> says the last new report to mention DTLS was raised 11 months
> ago which seems to confirm it.
Well, a lot has changed in the last few months, since the project has
received more attention and funding. Its been my observation that the
emails are tended to on a daily basis (if not more frequently).
Reports in RT are acted upon more quickly and more frequently also.

If the email has been tended to but its not in the queue, then I
suspect something else is going on.

My guess (and its purely speculation) is the report is being held
because of security considerations. The crash described is a DoS, and
that affects availability of an OpenSSL based server. I would expect
it to be more ture if the report has sample code to reproduce the
crash. But again, its purely speculation.

Jeff
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           majord...@openssl.org

Reply via email to