User Tools

Site Tools


security:policy

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
security:policy [2019/02/10 20:00]
henningw created
security:policy [2020/09/03 09:07] (current)
henningw
Line 22: Line 22:
 === Publishing security vulnerabilities === === Publishing security vulnerabilities ===
  
-Kamailio will publish security vulnerabilities, including an CVE ID, on the kamailio-business mailing list, sr-dev, sr-users as well as related lists. The advisories will also be published on the kamailio.org web site.+Kamailio will publish security vulnerabilities, including an CVE ID, on the kamailio-business mailing list, sr-dev, sr-users as well as related lists. The advisories will also be published on the kamailio.org web site. This will be done for vulnerabilities that have a higher severity, that means having a big enough impact as decided from the Kamailio Security Team.
  
-CVE entries should be created for vulnerabilities in the core and major modules, for rarely used modules this is not necessary. If there are several security issues together in one release, they should be announced together.+CVE entries should be created for critical vulnerabilities in the core and major modules, for rarely used modules this is not necessary. If there are several security issues together in one release, they should be announced together. 
  
 The Kamailio project release security fixed in the normal time based maintenance schedule, no immediate security releases are done. If possible a non-code workaround should be provided for the found security vulnerability. The Kamailio project release security fixed in the normal time based maintenance schedule, no immediate security releases are done. If possible a non-code workaround should be provided for the found security vulnerability.
security/policy.txt ยท Last modified: 2020/09/03 09:07 by henningw