[pmwiki-users] suggestion for security notifications
sip at varlock.com
Tue Sep 5 08:39:12 CDT 2006
On 09/05/06 14:53 Neil Herber wrote:
> However, it does no one other than the crackers any good to post
> vulnerabilities here before Patrick has had a chance to even look at
> the threat. He generally takes very little time to assess threats and
> post a new version of PmWiki or a workaround.
> So please, if you have found a vulnerability of any type, send a
> *private* email to Patrick first and discuss it with him.
Makes sense, even if here the issue was already known
and published, and, more important, exploits are circulating.
In a case like this I see no real advantage in keeping the
info off-list; in any case I'll be happy to adhere to
whatever the suggested policy is.
Bergamo, Italy - http://www.varlock.com
More information about the pmwiki-users