From: Ian Jackson Date: Fri, 16 Jan 2015 19:50:35 +0000 (+0000) Subject: Add headings X-Git-Url: http://xenbits.xensource.com/gitweb?a=commitdiff_plain;h=13433fa5af19d4c5a304acb34f2601bdd95ab00b;p=people%2Flarsk%2Fsecurity-process.git Add headings - For Predisclosure list application process - For Handling of embargoed information" No semantic change. Signed-off-by: Ian Jackson Signed-off-by: Ian Jackson --- diff --git a/security_vulnerability_process.html b/security_vulnerability_process.html index 4ed0042..010cf76 100644 --- a/security_vulnerability_process.html +++ b/security_vulnerability_process.html @@ -186,6 +186,7 @@ addresses.)

of the advisory and patches, with a clearly marked embargo date, as soon as they are available. The pre-disclosure list will also receive copies of public advisories when they are first issued or updated

+

Handling of embargoed information

Organizations on the pre-disclosure list are expected to maintain the confidentiality of the vulnerability up to the embargo date which security@xenproject have agreed with the discoverer, and are @@ -214,6 +215,7 @@ following:

NOTE: Prior v2.2 of this policy (25 June 2014) it was permitted to also make available the allocated CVE number. This is no longer permitted in accordance with MITRE policy.

+

Predisclosure list membership application process

Organisations who meet the criteria should contact security@xenproject if they wish to receive pre-disclosure of advisories. Please include in the e-mail: