Adding the board to the CC since this raises some highr level issues we probably need to think about and ideally make some decisions on.
On Fri, Apr 6, 2018 at 9:52 AM, Theall, George A <[hidden email]> wrote:
I think it really boils down to how we define common code base vs diverged code base. I like the idea of merging because on the one hand it lets us list all the BSDs, Linux, Mac OS (yeah, vulnerable to this too) in one CVE and be done with it, but in this specific case I was worried about confusion due to the timeline and the BSD vs. Linux side. (and also Mac OS is affected and I assume every variant of patch on a system with ed, so Solaris/etc. should be tested too)
I also worry it sets a precedent for the "common code base or not" e.g. MySQL and all it's children, or other older utilities (like beep apparently) that have security flaws and will have very widely varying amounts of divergence that we may want to think about first.
Perhaps we should look at amending the content decision to be less specific about code base specifically but also include things like common ancestry if it's a more conceptual problem (e.g. the code is correct, it does exactly what it was designed to do, it's just a truly terrible feature). So rather than "does a single common patch fix all these implementations? if yes count as common and MERGE" but "does a single easily defined solution (be it specific code patch, or specific conceptual change to the code) fix this all these implementations? if yes count as common and MERGE". Thish in this case it does, either remove ed support or use ed -r (FreeBSD did the -r by defining a "red" binary and then using it).
This of course would support the idea of "protocol" level flaws, which I forget if we discussed much/came to a decision on whether we want them or not.
I'm ok with REJECT'ing CVE-2018-1000156 in favour of the freeBSD one but I worry in this case that it might also be very confusing to people, which is why I did the new CVE, but if you think MERGE is best we can do that.
|Free forum by Nabble||Edit this page|