Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Need an email address to report 3 vulnerabilities we've found #633

Closed
leonwxqian opened this issue Jun 15, 2018 · 6 comments
Closed

Need an email address to report 3 vulnerabilities we've found #633

leonwxqian opened this issue Jun 15, 2018 · 6 comments

Comments

@leonwxqian
Copy link

leonwxqian commented Jun 15, 2018

Hello, during security auditing of other product that use your library, we have found 3 vulnerabilities in civetweb and want to report them to you. 1 of them is considered to be fatal (remote code execution) so we want to report by email. We've found this line in civetweb/docs/Contribution.md:

" In case you think you found a security issue that should be evaluated and fixed before public disclosure, feel free to write an email. “

But I couldn't find any email address in the docs, would you please offer your email address so we can send the detailed report to you? Thank you.


Tencent Blade Team

@leonwxqian leonwxqian changed the title Need an email address to report 4 vulnerabilities we've found Need an email address to report 3 vulnerabilities we've found Jun 15, 2018
@leonwxqian
Copy link
Author

Changed the title from 4 to 3 because based on the newest code, 1 of the vuln we've found before is gone. :)

@xtne6f
Copy link
Contributor

xtne6f commented Jun 15, 2018

In general, you can see author's email addresses by git log command.

@leonwxqian
Copy link
Author

xtne6f
Thank you :), I've got the email from the log, and the report is sent to that email.

@bel2125
Copy link
Member

bel2125 commented Jun 15, 2018

Thanks for the mail, I'm already having a look.
I use the same user name here and at gmail (dot com).

@leonwxqian
Copy link
Author

Checked the patches and the vulns are gone.
Thanks for your quick patch 👍

@bel2125
Copy link
Member

bel2125 commented Jul 2, 2018

All issues solved.
If someone else needs an email: take my username here - at gmail dot com.

@bel2125 bel2125 closed this as completed Jul 2, 2018
hunyadi-dev pushed a commit to hunyadi-dev/civetweb that referenced this issue Dec 18, 2020
MINIFICPP-1014 - Fix SFTP extension build on MacOS
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants