curl-users
Re: inappropriate
From: Daniel Stenberg <daniel_at_haxx.se>
Date: Mon, 6 Jun 2011 22:49:12 +0200 (CEST)
Date: Mon, 6 Jun 2011 22:49:12 +0200 (CEST)
On Mon, 6 Jun 2011, Richard Silverman wrote:
> I'm writing to report a security bug in curl, which probably should not go
> to the general list. How should I go about this?
Hi Richard,
Thanks for asking and wanting to help us out. To report security issues,
please email "curl-security at haxx.se". That's a list of trusted project team
members, as we prefer to first work out the details and level of the problem
in private so that we can release a fix and security alert at the same time
(if necessary) to reduce the impact for our millions of users.
This is mentioned, and our previous vulnerability reports are collected here:
http://curl.haxx.se/docs/security.html
-- / daniel.haxx.se ------------------------------------------------------------------- List admin: http://cool.haxx.se/list/listinfo/curl-users FAQ: http://curl.haxx.se/docs/faq.html Etiquette: http://curl.haxx.se/mail/etiquette.htmlReceived on 2011-06-06