Política de segurança - 3. Fontes de incidentes
3.1 Fontes de incidentes aceitas
Como relator de um incidente segurança em um software empacotado pelo Fink, você deve garantir que a vulnerabilidade do software também existe no Mac OS X. É responsabilidade da parte notificadora garantir que uma das seguintes fontes reforce o problema relatado para o software em questão.
- AIXAPAR: AIX APAR (Authorised Problem Analysis Report)
- APPLE: Apple Security Update
- ATSTAKE: @stake security advisory
- AUSCERT: AUSCERT advisory
- BID: Security Focus Bugtraq ID database entry
- BINDVIEW: BindView security advisory
- BUGTRAQ: Posting to Bugtraq mailing list
- CALDERA: Caldera security advisory
- CERT: CERT/CC Advisories
- CERT-VN: CERT/CC vulnerability note
- CIAC: DOE CIAC (Computer Incident Advisory Center) bulletins
- CONECTIVA: Conectiva Linux advisory
- CONFIRM: URL do local onde o fornecedor confirma que o problema existe
- DEBIAN: Debian Linux Security Information
- EEYE: eEye security advisory
- EL8: EL8 advisory
- ENGARDE: En Garde Linux advisory
- FEDORA: Fedora Project security advisory
- FULLDISC: Full-Disclosure mailing list
- FreeBSD: FreeBSD security advisory
- GENTOO: Gentoo Linux security advisory
- HERT: HERT security advisory
- HP: HP security advisories
- IBM: IBM ERS/BRS advisories
- IMMUNIX: Immunix Linux advisory
- INFOWAR: INFOWAR security advisory
- ISS: ISS Security Advisory
- KSRT: KSR[T] Security Advisory
- L0PHT: L0pht Security Advisory
- MANDRAKE: Linux-Mandrake advisory
- MISC: referência a uma URL genérica
- MLIST: referência genérica a listas de discussão
- NAI: NAI Labs security advisory
- NETECT: Netect security advisory
- NetBSD: NetBSD Security Advisory
- OPENBSD: OpenBSD Security Advisory
- REDHAT: Security advisories
- RSI: Repent Security, Inc. security advisory
- SEKURE: Sekure security advisory
- SF-INCIDENTS: mensagem na lista de discussão Security Focus Incidents
- SGI: SGI Security Advisory
- SLACKWARE: Slackware security advisory
- SNI: Secure Networks, Inc. security advisory
- SUN: Sun security bulletin
- SUNALERT: Sun security alert
- SUNBUG: Sun bug ID
- SUSE: SuSE Linux: Security Announcements
- TRUSTIX: Trustix Security Advisory
- TURBO: TurboLinux advisory
- VULN-DEV: Posting to VULN-DEV mailing list
- VULNWATCH: VulnWatch mailing list
- XF: X-Force Vulnerability Database
- CVE: CVE Candidates
As palavras-chaves acima estão de acordo com a lista de palavras-chaves recomendadas pelo CVE.