X-Recipient: archive-cygwin@delorie.com
X-SWARE-Spam-Status: No, hits=2.4 required=5.0	tests=AWL,BAYES_00,DKIM_SIGNED,DKIM_VALID,FREEMAIL_FROM,RCVD_IN_DNSWL_LOW
X-Spam-Check-By: sourceware.org
MIME-Version: 1.0
From: Gynvael Coldwind <gynvael@coldwind.pl>
Date: Mon, 13 Feb 2012 07:08:56 +0100
Message-ID: <CAAnPYQ4BVQZ0dTqNeRSWRMxQ4diE8oRh5k111SUfe_-Ug3vX9w@mail.gmail.com>
Subject: Where to report security bugs in cygwin1.dll ?
To: cygwin@cygwin.com
Content-Type: text/plain; charset=ISO-8859-1
Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe@cygwin.com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin@cygwin.com>
List-Help: <mailto:cygwin-help@cygwin.com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner@cygwin.com
Mail-Followup-To: cygwin@cygwin.com
Delivered-To: mailing list cygwin@cygwin.com

Hey,

I've found a security problem with cygwin1.dll, but I can't find any
security contact on Cygwin page, and I feel kinda reluctant to post
the bug report here or on another public mailing list.

Could you advise on the security contact where should I send the bug
report OR confirm that it's the Cygwin policy to post security bugs
here/in another public mainling list?

I'll add that the bug is rather no-severity on most systems, and
high-severity on others (hence the reluctance).

Cheers,
-- 
gynvael.coldwind//vx

--
Problem reports:       http://cygwin.com/problems.html
FAQ:                   http://cygwin.com/faq/
Documentation:         http://cygwin.com/docs.html
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple

