Skip to content

Comment on Curl/libcurl HIGH CVE-2023-38545 leaked early?parent

Comments

That has to do with curl itself, redhat isn't necessarily bound to that schedule and we don't know the discussion that happened privately prior to disclosure date.

That kind of approach leads to the party which broke ranks this time, not being included in confidential things in future.

Along the lines of "they've proven they can't be trusted", kind of thing.

I don't agree they broke ranks. The 6am date was for the curl project itself.

Probably depends on whether Red Hat was party to privileged info as part of a co-ordinated release for this. Personally, I have no idea.

I'd be surprised if not, but even then, it's not clear if the time was a requirement set by the cURL team at all for projects that aren't cURL.

RedHat is one of the subscribers of the mailing list where the CVE details were sent under embargo, so yes, they were bound to that and broke the embargo 13 hours earlier than the lift date.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.