From: | Josh Berkus <josh(at)agliodbs(dot)com> |
---|---|
To: | pgsql-hackers(at)postgresql(dot)org |
Subject: | Re: Release of CVEs |
Date: | 2015-10-11 17:54:19 |
Message-ID: | 561AA24B.30903@agliodbs.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-hackers |
On 10/11/2015 04:54 AM, Greg Sabino Mullane wrote:
> The release notes for the new version reference some CVEs that
> have not been publically released yet. Are they slow, or is
> this something that needs to be added to the release
> process checklist?
These days MITRE is lagging 2-6 weeks behind publication for getting
CVEs on their website. That's why I didn't bother to link them from the
announcement.
I don't know that there's anything the PostgreSQL project can do about
it. If anyone on this list is connected with MITRE, please ask them
what they need to be more prompt.
--
Josh Berkus
PostgreSQL Experts Inc.
http://pgexperts.com
From | Date | Subject | |
---|---|---|---|
Next Message | Stefan Keller | 2015-10-11 19:00:51 | Re: point_ops for GiST |
Previous Message | Tom Lane | 2015-10-11 15:42:08 | Re: Postgres service stops when I kill client backend on Windows |