[pmwiki-users] suggestion for security notifications

Simone Rota sip at varlock.com
Tue Sep 5 08:39:12 CDT 2006

On 09/05/06 14:53 Neil Herber wrote:
> However, it does no one other than the crackers any good to post 
> vulnerabilities here before Patrick has had a chance to even look at 
> the threat. He generally takes very little time to assess threats and 
> post a new version of PmWiki or a workaround.
> So please, if you have found a vulnerability of any type, send a 
> *private* email to Patrick first and discuss it with him.

Makes sense, even if here the issue was already known
and published, and, more important, exploits are circulating.

In a case like this I see no real advantage in keeping the
info off-list; in any case I'll be happy to adhere to
whatever the suggested policy is.


Simone Rota
Bergamo, Italy - http://www.varlock.com

More information about the pmwiki-users mailing list