Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-31 Thread Jan Beulich
>>> On 31.01.17 at 16:11, wrote: > OK, I've rewritten the section thus: > > --- > > 4. The security team will only issue an advisory if there is a known > combination of software in which the vulnerability can be exploited. > > In most cases, the software which contains the bug is also the targ

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-31 Thread George Dunlap
t;>>>>> On 24.01.17 at 12:33, wrote: >>>>>> Jan Beulich writes ("Re: [Xen-devel] RFC: Adding a section to the Xen >>>> security >>>>>> policy about what constitutes a vulnerability"): >>>>>>> "If a bu

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-25 Thread Jan Beulich
>>> On 24.01.17 at 17:33, wrote: >> On Jan 24, 2017, at 3:08 PM, Jan Beulich wrote: >>>>> On 24.01.17 at 16:01, wrote: >>>> On Jan 24, 2017, at 11:43 AM, Jan Beulich wrote: >>>>>>> On 24.01.17 at 12:33, wrote: >>>

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-24 Thread George Dunlap
> On Jan 24, 2017, at 3:08 PM, Jan Beulich wrote: > >>>> On 24.01.17 at 16:01, wrote: > >>> On Jan 24, 2017, at 11:43 AM, Jan Beulich wrote: >>> >>>>>> On 24.01.17 at 12:33, wrote: >>>> Jan Beulich writes ("Re: [X

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-24 Thread Jan Beulich
>>> On 24.01.17 at 16:01, wrote: >> On Jan 24, 2017, at 11:43 AM, Jan Beulich wrote: >> >>>>> On 24.01.17 at 12:33, wrote: >>> Jan Beulich writes ("Re: [Xen-devel] RFC: Adding a section to the Xen > security >>> policy about

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-24 Thread George Dunlap
> On Jan 24, 2017, at 11:43 AM, Jan Beulich wrote: > >>>> On 24.01.17 at 12:33, wrote: >> Jan Beulich writes ("Re: [Xen-devel] RFC: Adding a section to the Xen >> security >> policy about what constitutes a vulnerability"): >>>

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-24 Thread Jan Beulich
>>> On 24.01.17 at 12:33, wrote: > Jan Beulich writes ("Re: [Xen-devel] RFC: Adding a section to the Xen > security > policy about what constitutes a vulnerability"): >> "If a bug requires a vulnerable operating system to be exploitable, the >> Xe

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-24 Thread Ian Jackson
Jan Beulich writes ("Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability"): > "If a bug requires a vulnerable operating system to be exploitable, the > Xen Security Team will pro-actively investigate the vulnerability of

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-23 Thread Jan Beulich
>>> On 23.01.17 at 12:27, wrote: > On Wed, Jan 4, 2017 at 2:48 PM, George Dunlap > wrote: >> On Wed, Jan 4, 2017 at 1:16 PM, Jan Beulich wrote: >> On 04.01.17 at 13:36, wrote: 4. The security team will only issue an advisory if there is a known combination of software in which th

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-23 Thread George Dunlap
On Wed, Jan 4, 2017 at 2:48 PM, George Dunlap wrote: > On Wed, Jan 4, 2017 at 1:16 PM, Jan Beulich wrote: > On 04.01.17 at 13:36, wrote: >>> 4. The security team will only issue an advisory if there is a known >>> combination of software in which the vulnerability can be exploited. >>> >>> I

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-20 Thread Ian Jackson
George Dunlap writes ("[Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability"): > If a bug requires a vulnerable operating system to be exploitable, the > Xen Security Team will pro-actively investigate the vulnerability of > the fo

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-05 Thread Stefano Stabellini
On Wed, 4 Jan 2017, George Dunlap wrote: > The Xen Security Team has dealt with a number of issues recently where > it wasn't exactly clear whether we should issue an advisory or not: > the Xen Security Response Process only mentiones "'vulnerabilities", > without specifying what constitutes a vuln

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-05 Thread Wei Liu
On Wed, Jan 04, 2017 at 12:43:02PM +, George Dunlap wrote: > On Wed, Jan 4, 2017 at 12:36 PM, George Dunlap > wrote: > > 4. The security team will only issue an advisory if there is a known > > combination of software in which the vulnerability can be exploited. > > > > In most cases, the sof

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-04 Thread George Dunlap
On Wed, Jan 4, 2017 at 1:16 PM, Jan Beulich wrote: On 04.01.17 at 13:36, wrote: >> 4. The security team will only issue an advisory if there is a known >> combination of software in which the vulnerability can be exploited. >> >> In most cases, the software which contains the bug is also the

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-04 Thread Jan Beulich
>>> On 04.01.17 at 13:36, wrote: > 4. The security team will only issue an advisory if there is a known > combination of software in which the vulnerability can be exploited. > > In most cases, the software which contains the bug is also the target > of the attack: that is, a bug in Xen allows an

Re: [Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-04 Thread George Dunlap
On Wed, Jan 4, 2017 at 12:36 PM, George Dunlap wrote: > 4. The security team will only issue an advisory if there is a known > combination of software in which the vulnerability can be exploited. > > In most cases, the software which contains the bug is also the target > of the attack: that is, a

[Xen-devel] RFC: Adding a section to the Xen security policy about what constitutes a vulnerability

2017-01-04 Thread George Dunlap
The Xen Security Team has dealt with a number of issues recently where it wasn't exactly clear whether we should issue an advisory or not: the Xen Security Response Process only mentiones "'vulnerabilities", without specifying what constitutes a vulnerability. Issuing advisories has a cost: It cos