[MPlayer-dev-eng] buffer overflow of the month
Sven Tantau
sven at sven-tantau.de
Fri Aug 26 18:16:33 CEST 2005
Diego Biurrun wrote:
> On Fri, Aug 26, 2005 at 01:05:27PM +0300, Jan Knutar wrote:
>
>>On Thursday 25 August 2005 20:41, Reimar Döffinger wrote:
>>
>>
>>>Mailing to -users is not "vendor contacted"
>>
>>It is still, however, the listed place to send bug reports to ;-) So he did
>>post to correct place, I guess...
>
>
> Nonsense. Security problems should be reported in private first, not made
> public immediately.
Other projects offer special security contacts.
Your guide lines say:
'Do not contact the developers! Use the ml.'
(No time to seach this up.. but I am sure there are several lines like
this.)
And as Attila quoted me:
Your opinion.
(I do not say this is not my opinion too. That is not the point.)
Regards
Sven
--
Sven Tantau
+49 177 7824828
http://www.sven-tantau.de/ *** http://www.beastiebytes.de/
http://twe.sven-tantau.de/ *** http://www.bewiso.de/
More information about the MPlayer-dev-eng
mailing list