Access to private bugs

View: New views
4 Messages — Rating Filter:   Alert me  

Access to private bugs

by Norbert Tretkowski-3 :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi,

I'm one of the MySQL maintainers in Debian. Yesterday I prepared an
update of the MySQL packages to fix CVE-2007-5969. Unfortunately the
bugreport (#32111) is private, so I had to search the archive of the
commiters mailinglist to get the patch. I don't know if there was a
discussion about the bug or the patch.

Is it possible to give maintainers of MySQL packages access to those
bugs? It would make our life a bit easier.

        Norbert


--
MySQL Packagers Mailing List
For list archives: http://lists.mysql.com/packagers
To unsubscribe:    http://lists.mysql.com/packagers?unsub=lists@...


Re: Access to private bugs

by ismail "cartman" dönmez :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Monday 10 December 2007 11:20:57 tarihinde Norbert Tretkowski şunları
yazmıştı:

> Hi,
>
> I'm one of the MySQL maintainers in Debian. Yesterday I prepared an
> update of the MySQL packages to fix CVE-2007-5969. Unfortunately the
> bugreport (#32111) is private, so I had to search the archive of the
> commiters mailinglist to get the patch. I don't know if there was a
> discussion about the bug or the patch.
>
> Is it possible to give maintainers of MySQL packages access to those
> bugs? It would make our life a bit easier.

Indeed I am facing the same problem here as a packager for Pardus Linux.

Regards,
ismail

--
Never learn by your mistakes, if you do you may never dare to try again.

--
MySQL Packagers Mailing List
For list archives: http://lists.mysql.com/packagers
To unsubscribe:    http://lists.mysql.com/packagers?unsub=lists@...


Re: Access to private bugs

by Sergei Golubchik :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi!

Unfortunately, not at the moment :(

We cannot allow you to see all private fields, attaches, and bugs (they
could contain sensitive information that we're contractually required to
keep confidential). We would need to introduce new flag "security bug"
(or something) and new category of users that can see security-private
bugs, but not other private bugs.

But we'll open all private security bugs when a fixed 5.1 release is
out.

On Dec 10, Norbert Tretkowski wrote:

>
> I'm one of the MySQL maintainers in Debian. Yesterday I prepared an
> update of the MySQL packages to fix CVE-2007-5969. Unfortunately the
> bugreport (#32111) is private, so I had to search the archive of the
> commiters mailinglist to get the patch. I don't know if there was a
> discussion about the bug or the patch.
>
> Is it possible to give maintainers of MySQL packages access to those
> bugs? It would make our life a bit easier.
>
Regards / Mit vielen Grüssen,
Sergei

--
   __  ___     ___ ____  __
  /  |/  /_ __/ __/ __ \/ /   Sergei Golubchik <serg@...>
 / /|_/ / // /\ \/ /_/ / /__  Principal Software Developer
/_/  /_/\_, /___/\___\_\___/  MySQL GmbH, Dachauer Str. 37, D-80335 München
       <___/                  Geschäftsführer: Kaj Arnö - HRB München 162140

--
MySQL Packagers Mailing List
For list archives: http://lists.mysql.com/packagers
To unsubscribe:    http://lists.mysql.com/packagers?unsub=lists@...


Re: Access to private bugs

by ismail "cartman" dönmez :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Monday 10 December 2007 13:16:20 tarihinde Sergei Golubchik şunları yazmıştı:
> Hi!
>
> Unfortunately, not at the moment :(
>
> We cannot allow you to see all private fields, attaches, and bugs (they
> could contain sensitive information that we're contractually required to
> keep confidential). We would need to introduce new flag "security bug"
> (or something) and new category of users that can see security-private
> bugs, but not other private bugs.

Introducing a new flag in bugzilla shouldn't be hard I guess. That would allow
us to write better advisories too.

Regards,
ismail

--
Never learn by your mistakes, if you do you may never dare to try again.

--
MySQL Packagers Mailing List
For list archives: http://lists.mysql.com/packagers
To unsubscribe:    http://lists.mysql.com/packagers?unsub=lists@...

LightInTheBox - Buy quality products at wholesale price!