Request for CVEs for Pidgin

Tomas Hoger thoger at redhat.com
Wed Jan 15 09:19:45 EST 2014


On Tue, 14 Jan 2014 13:35:15 -0800 Mark Doliner wrote:

> On Tue, Jan 14, 2014 at 12:53 PM, Tomas Hoger <thoger at redhat.com>
> wrote:
> > Josh and Jan changed their roles inside Red Hat and while they both
> > work on security from one side or another, they will no longer be
> > able to help with the CVE assignments, or need access to
> > information on non-public issues.  I'm keeping them CCed on this
> > reply, but you can drop them form the CC on any further replies.
> 
> Noted, thanks. Josh is still subscribed to our packagers at pidgin.im
> mailing list where we pre-announce security problems and give
> distributions time to prepare updated packages. If I understand
> correctly, it sounds like he should be removed from this list?

Yes, you can remove him form the list.  I apologize for us not
requesting that earlier.

> In addition to you and Josh, Huzaifa Sidhpurwala <huzaifas at redhat.com>
> is also subscribed.

That's correct.  I asked you back in August to remove Jan and add
Huzaifa instead, and the change was done at the time.

> > I'd like to share this list with a colleague, Kurt Seifried, who
> > handles many CVE assignments, to help with deciding on the
> > merge/split cases.  You can find him do a lot of assignments on the
> > oss-security list.  Please let me know if it's ok to send him your
> > list.
> 
> Sure, that sounds totally reasonable.

Forwarded, I hope to get you IDs soon.

-- 
Tomas Hoger / Red Hat Security Response Team


More information about the security mailing list