Re: [HACKERS] Release of CVEs

2015-10-13 Thread Gavin Flower
On 14/10/15 18:19, Tom Lane wrote: I wrote: Michael Paquier writes: On Mon, Oct 12, 2015 at 2:54 AM, Josh Berkus wrote: I don't know that there's anything the PostgreSQL project can do about it. If anyone on this list is connected with MITRE, please ask them what

Re: [HACKERS] Release of CVEs

2015-10-13 Thread Tom Lane
I wrote: > Michael Paquier writes: >> On Mon, Oct 12, 2015 at 2:54 AM, Josh Berkus wrote: >>> I don't know that there's anything the PostgreSQL project can do about >>> it. If anyone on this list is connected with MITRE, please ask them >>> what they need to be more

[HACKERS] Release of CVEs

2015-10-11 Thread Greg Sabino Mullane
The release notes for the new version reference some CVEs that have not been publically released yet. Are they slow, or is this something that needs to be added to the release process checklist? For example, see the CVE hyperlink for json parsing at:

Re: [HACKERS] Release of CVEs

2015-10-11 Thread Michael Paquier
On Sun, Oct 11, 2015 at 8:54 PM, Greg Sabino Mullane wrote: > The release notes for the new version reference some CVEs that > have not been publically released yet. Are they slow, or is > this something that needs to be added to the release > process checklist? My guess is

Re: [HACKERS] Release of CVEs

2015-10-11 Thread Josh Berkus
On 10/11/2015 04:54 AM, Greg Sabino Mullane wrote: > The release notes for the new version reference some CVEs that > have not been publically released yet. Are they slow, or is > this something that needs to be added to the release > process checklist? These days MITRE is lagging 2-6 weeks

Re: [HACKERS] Release of CVEs

2015-10-11 Thread Michael Paquier
On Mon, Oct 12, 2015 at 2:54 AM, Josh Berkus wrote: > I don't know that there's anything the PostgreSQL project can do about > it. If anyone on this list is connected with MITRE, please ask them > what they need to be more prompt. http://cve.mitre.org/ has a "Contact Us" tab linking to the

Re: [HACKERS] Release of CVEs

2015-10-11 Thread Tom Lane
Michael Paquier writes: > On Mon, Oct 12, 2015 at 2:54 AM, Josh Berkus wrote: >> I don't know that there's anything the PostgreSQL project can do about >> it. If anyone on this list is connected with MITRE, please ask them >> what they need to be more prompt. >