Good example: Chromium blob found by Debian (via LWN)

Daniel Krebs mailinglist at krebs.uno
Fri Jun 19 10:40:36 UTC 2015


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Am 18.06.2015 um 10:30 schrieb Bernhard Reiter:
> Here is an example where the peer review of Debian found an issue
> that - most likely - slipped the Google devs.

If I understand the links correctly the change "did make its way into
Debian unstable without being noticed." So in fact it was found after
it has been implemented wasn't it?
Thats even more worrisome.

DK
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)

iQIcBAEBCgAGBQJVg/GLAAoJEA7irlPqaBCOR2oQAJwmIpQPIun5qUr+J77yVWAe
oLy5WOkuS0aH5u7529QhXzIWzzpclFlYoCyKuu0CscjSlggemvQlwE81AtiK9/oF
RNwEf9eJGfNtGd4L+6hq2bZrXEs2CKp2r9iShdxKtoUQY2mW8Xtb1PyVbBjv1d2Z
0BZMQH4QLebGdPObbQuh370Vt7e9pivJRVTgs8SnlXTyx5m7kv02oXlzeDKqryFi
ZgcZezCd3A+b/1JvJcm7QCz3SDbTaJDJ1/6sHk3hR+5S4AFWMAmMtouyj7hOUlSm
ovp450WOpHk4sM56H0nRUc7C3efFTe6bLmX+E4YW3cI7WjVujTHMInKL0LCoqSdy
Y5Csz6uj73kcta8TB4XmtQxjQ33VZgFwZyyhvxK9gNs4gaNERlnZlxQ+07fxVSow
BMOo+f3eGaG3ocsFETHj3TgWHXKKlvtcvi4Soea8alXEJQ7ypsOVoX6hQT1G/ZXr
p4TrLP3qjw2rppZ0gJcPDlTJAafq0ahA89Nnr1TN0PsCYm47Rw/N4uK8AWWvmvDU
uHnBbfRfaGCHk4jJ3PLuH40sRMxj8ERPaIIuCiM7t2K0Pd+8+d7qTRoo6oa6mlGn
9vLXURXqkFCa3vd708a7jMN292YpQv8XUGoYtKu58R60ECYxdv/95sD3r+wYcq57
YKc3K3vRYg2bQixjckOn
=oD+c
-----END PGP SIGNATURE-----



More information about the Discussion mailing list