Bitcoin Forum
November 04, 2024, 10:42:46 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: standard procedure to handle security vulnerabilities?  (Read 733 times)
Diapolo (OP)
Hero Member
*****
Offline Offline

Activity: 772
Merit: 500



View Profile WWW
September 23, 2012, 11:20:13 AM
 #1

As we recently added version information to bitcoin-qt.exe, I requested Secunia to add Bitcoin-Qt to their Secunia PSI database and today Bitcoin-Qt is found and listed after a scan Smiley!
Secunia PSI (https://secunia.com/vulnerability_scanning/personal/) is a tool for Windows, which checks installed programs and warns if it finds versions, which contain a known security vulnerability and offers auto-updates or at least a link with valuable information what a user can do to fix it.



IMHO it would be nice, if we report our CVEs (https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures) or at least known security problems to them, so they can add such infos to their database.

https://secunia.com/community/advisories/report_vulnerability/

The headline of this thread is "standard procedure to handle security vulnerabilities?" and I'm asking is there one and do others agree that is is valuable to report security problems (or is this already beeing done?)?

Dia

Liked my former work for Bitcoin Core? Drop me a donation via:
1PwnvixzVAKnAqp8LCV8iuv7ohzX2pbn5x
bitcoin:1PwnvixzVAKnAqp8LCV8iuv7ohzX2pbn5x?label=Diapolo
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!