From Fedora Project Wiki

(Added category.)
(Added links to vulnerability bugs)
Line 13: Line 13:
|-
|-
! Current issues
! Current issues
| Critical Vulnerabilities <BR> Important Vulnerabilities <BR> Moderate Vulnerabilities <BR> Low Vulnerabilities
| [https://bugzilla.redhat.com/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&classification=Fedora&keywords=SecurityTracking%2C%20&keywords_type=allwords&list_id=2661454&priority=urgent&query_format=advanced Critical Vulnerabilities] <BR> [https://bugzilla.redhat.com/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&classification=Fedora&keywords=SecurityTracking%2C%20&keywords_type=allwords&list_id=2661457&priority=high&query_format=advanced Important Vulnerabilities] <BR> [https://bugzilla.redhat.com/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&classification=Fedora&keywords=SecurityTracking%2C%20&keywords_type=allwords&list_id=2661461&priority=medium&query_format=advanced Moderate Vulnerabilities] <BR> [https://bugzilla.redhat.com/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&classification=Fedora&keywords=SecurityTracking%2C%20&keywords_type=allwords&list_id=2661462&priority=low&query_format=advanced Low Vulnerabilities] <BR> [https://bugzilla.redhat.com/buglist.cgi?bug_status=NEW&bug_status=ASSIGNED&classification=Fedora&keywords=SecurityTracking%2C%20&keywords_type=allwords&list_id=2661465&priority=unspecified&query_format=advanced Unknown Vulnerabilities]
|}
|}



Revision as of 01:37, 18 July 2014

The Fedora Security Team's mission is to help get security fixes into Fedora's repositories as soon as possible to help protect the end users.

IRC Channel #fedora-security-team[?]
Mailing List security-team - Security Team mailing list
security - General security mailing list (good for questions)
Meetings TBD
Current issues Critical Vulnerabilities
Important Vulnerabilities
Moderate Vulnerabilities
Low Vulnerabilities
Unknown Vulnerabilities

How

Red Hat Product Security opens bugs in response to CVEs that get reported by MITRE. A CVE bug is opened along with any tracker bugs that are opened against the individual packages. The tracking bug notifies the package owner of the vulnerability. Generally speaking, the package owner should follow up with upstream to obtain a patch or the fixed source to push out to the repositories.

The problem is that many package owners either don't have time or they don't understand the need of the tracking bug. That's where the Security Team comes in to help. We work with upstream to obtain the fixes and then provide them to the packagers via the tracking bug. We also work with packagers to help them get these fixes into the repositories.