Re: CVE Links are broken on the PG 10.1 news page

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Magnus Hagander <magnus(at)hagander(dot)net>
Cc: Daniel Gustafsson <daniel(at)yesql(dot)se>, Damien Clochard <damien(at)dalibo(dot)info>, pgsql-www(at)lists(dot)postgresql(dot)org
Subject: Re: CVE Links are broken on the PG 10.1 news page
Date: 2017-11-10 16:32:30
Message-ID: 30949.1510331550@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-www

Magnus Hagander <magnus(at)hagander(dot)net> writes:
> On Fri, Nov 10, 2017 at 2:56 PM, Daniel Gustafsson <daniel(at)yesql(dot)se> wrote:
>> On 10 Nov 2017, at 12:14, Damien Clochard <damien(at)dalibo(dot)info> wrote:
>>> The 3 CVE links lead to a 404 page on RH website :
>>> https://access.redhat.com/security/cve/CVE-2017-12172
>>> https://access.redhat.com/security/cve/CVE-2017-15098
>>> https://access.redhat.com/security/cve/CVE-2017-15099

>> Even better would probably be to not make them actual links until the
>> target URL exists.

> We used to do it that way. Which then meant they usually didn't get updated
> until the next round of releases, because it got forgotten :/

FWIW, I see that -12172 just got de-embargoed. Probably the other two
will follow shortly.

regards, tom lane

In response to

Responses

Browse pgsql-www by date

  From Date Subject
Next Message Jonathan S. Katz 2017-11-10 16:55:21 Re: CVE Links are broken on the PG 10.1 news page
Previous Message Magnus Hagander 2017-11-10 13:57:57 Re: CVE Links are broken on the PG 10.1 news page