Comment 54 for bug 1100282

Revision history for this message
Thierry Carrez (ttx) wrote : Re: DoS through XML entity expansion

@Christian: let me explain our disclosure system to see how we can align.

We push the patches to a set of downstream stakeholders (think distros) so that they can coordinate their own updates with ours. That restricted disclosure window usually lasts 3-5 business days, and then we push the patches publicly. So it would be great to come up with a common "public date" and then we can align our responsible disclosure process to that. For example if we agree we can go public Tuesday next week, I can send patches to the distros wednesday. Let me know what public date sounds doable for the Python side.