RE: [Question] Documenting platform implications on CVE to git

2017-10-06 Thread Randall S. Becker
-Original Message- On October 6, 2017 7:45 PM Jonathan Nieder wrote: Cc: git@vger.kernel.org >Randall S. Becker wrote: >> The first one, mostly. When looking at CVE-2017-14867, there are >> places like >> https://nvd.nist.gov/vuln/detail/CVE-2017-14867 where the issue is >> discussed.

Re: [Question] Documenting platform implications on CVE to git

2017-10-06 Thread Jonathan Nieder
Hi, Randall S. Becker wrote: > The first one, mostly. When looking at CVE-2017-14867, there are places like > https://nvd.nist.gov/vuln/detail/CVE-2017-14867 where the issue is > discussed. It provides hyperlinks to various platform discussions. > Unfortunately for me, I am not an HPE employee -

RE: [Question] Documenting platform implications on CVE to git

2017-10-06 Thread Randall S. Becker
-Original Message- On October 6, 2017 6:51 PM, Jonathan Nieder wrote >Randall S. Becker wrote: >> I wonder whether there is some mechanism for providing official >> responses from platform ports relating to security CVE reports, like CVE-2017-14867. >This question is too abstract for me.

Re: [Question] Documenting platform implications on CVE to git

2017-10-06 Thread Jonathan Nieder
Hi Randall, Randall S. Becker wrote: > I wonder whether there is some mechanism for providing official responses > from platform ports relating to security CVE reports, like CVE-2017-14867. This question is too abstract for me. Can you say more concretely what you are trying to do? E.g. are

[Question] Documenting platform implications on CVE to git

2017-10-06 Thread Randall S. Becker
Hi All, I wonder whether there is some mechanism for providing official responses from platform ports relating to security CVE reports, like CVE-2017-14867. For example, the Perl implementation on HPE NonStop does not include the SCM module so commands relating cvsserver may not be available -