On Oct 18, 2016, at 4:09 AM, Florian Weimer <f...@deneb.enyo.de> wrote:
> * Martin Winter:
>> Document Revision History:
>> 1.0 22 September 2016 - Initial (internal) draft
>> 1.1 18 October 2016 - CVE release version
> Why didn't you coordinate the disclosure with distributions?
> Debian assigned a CVE ID to you in good faith, but the promised
> coordination never happened. We never received the details of the
> vulnerability, nor the planned disclosure date.
For that matter, why didn't VyOS know about this? (They do now.)
Quagga-users mailing list