On Thu, May 08, 2008 at 03:03:52PM -0700, Valerie Bubb Fenwick wrote: > On Thu, 8 May 2008, Robert Lawhead wrote: > > > Alan, thanks for your speedy reply. I have searched the opensolaris bug db > > both by keyword and now that you've provided the bug id, using that... I > > still come-up empty. Are you referring to some internal db, or am I > > overlooking something obvious? Thanks. > > > > Comment #1 From Alan Coopersmith 2008-04-24 16:11:37 ------- > > Sun is tracking this bug in the Solaris bug database as bug id 6684003 > > ("fix CVE-2008-1483 in SunSSH"). If you look at the code URL mentioned > > again, you'll see the fix is now checked in there for Nevada build 89. > > Hi Robert - > > Yes, the 6684003 is in an internal database. It is current Sun policy > to not publish security bugs (which this is). It seems we should consider > doing something for these issues once they become public.
Yes, we should.