Re: bugreport = free?



Andreas Stieger wrote:
Hi,

Derk wrote:
I see that you have to create an account at Novell.com when one wants to
report a bug to Bugzilla. Is this seen as support that one has to pay for
or is submitting a bug found in openSUSE free of charge?

I submitted lots of bugs and never paid. The account you create is for the
bug tracking system and the openSUSE wiki.

And for the paranoid, you can fill in anything you desire. The main
thing is a working email adress. It is not as if the Novell Police will
be coming after you or something.

They just use the same system for their paying customers as well. Some
people will have access to different parts of the bugs. e.g. not all
securitybugs are open all the time.

There is an agreement between distributions that certain security
solutions will have a (I think 2 days) deleay, so that everybody in
every distribution can submit the patch at the same time, making it ery
hard to abuse.

e.g. if DistroX would come out with a patch for ssh on friday evening
_for an unknown bug_ then a cracker could abuse ity, reverse engineer
the patch and abuse other systems, while they are still working on the
solution.

If they just inform everybody and wait a bit. They bring out the patch
all together on mondaymorning. Much more secure, even tjough it is
security through obscurity.

houghi
--
houghi http://houghi.org http://www.plainfaqs.org/linux/
http://www.netmeister.org/news/learn2quote.html

Today I went outside. My pupils have never been tinier...
.



Relevant Pages

  • Weekly Python Patch/Bug Summary
    ... Patch / Bug Summary ... http://python.org/sf/606098 closed by rhettinger ... http://python.org/sf/1088716 closed by loewis ...
    (comp.lang.python)
  • [Full-Disclosure] RE: [kinda-but-not-really-Full-Disclosure-so-we-feel-warm-and-fuzzy] Re: <to va
    ... Because it must be realised that as soon as a patch and or advisory is ... there are global teams of people working to discover and exploit said bug. ... quiet and MS just released patches for 'undisclosed' problems... ... > engineer a ms patch to find the changed code and produce a working ...
    (Full-Disclosure)
  • RE: Mailslot bug (MS06-035) vs non-Mailslot bug (CVE-2006-3942)
    ... made patch for SRV.SYS. ... vulnerabilities that everyone is so afraid to talk about. ... the mailslot bug, and they didn't have any technical details to turn to, ... So keep on truckin Core Security, Michal Zalewski, and even ...
    (Bugtraq)
  • Re: Cant take skilled talent?
    ... least playing an easier version of the game than everyone else has. ... mind changing or removing the patch if TB emailed me about it. ... -fixing skilled bug is good ... The patch simply stops the monsters from growing too powerful compared to the ...
    (rec.games.roguelike.adom)
  • Re: acpi kmalloc to kzalloc conversion and a memory leak fix.
    ... I had submitted this patch sometime earlier. ... Submitting again after ... fixing a bug in the patch. ... char *pathname = NULL; ...
    (Linux-Kernel)