https://wiki.archlinux.org/api.php?action=feedcontributions&user=2114L3&feedformat=atomArchWiki - User contributions [en]2024-03-29T08:22:07ZUser contributionsMediaWiki 1.41.0https://wiki.archlinux.org/index.php?title=Arch_Security_Team&diff=561963Arch Security Team2019-01-06T00:36:51Z<p>2114L3: ubuntu advisory feed change from www to usn, as www link was broken. link update to https://usn.ubuntu.com/usn/atom.xml as list on https://usn.ubuntu.com/</p>
<hr />
<div>[[Category:Arch development]]<br />
[[Category:Security]]<br />
[[Category:Teams]]<br />
[[pt:Arch Security Team]]<br />
The Arch Security Team is a group of volunteers whose goal is to track security issues with Arch Linux packages. All issues are tracked on the [https://security.archlinux.org/ Arch Linux security tracker]. The team was formerly known as the ''Arch CVE Monitoring Team''.<br />
<br />
== Mission ==<br />
The mission of the Arch Security Team is to contribute to the improvement of the security of Arch Linux. <br />
<br />
The most important duty of the team is to find and track issues assigned a [[wikipedia:Common_Vulnerabilities_and_Exposures|Common Vulnerabilities and Exposure]] (CVE). A CVE is public, it is identified by a unique ID of the form ''CVE-YYYY-number''. <br />
<br />
They publish ASAs (''Arch Linux Security Advisory'') which is an Arch-specific warning disseminated to Arch users. ASAs are scheduled in the tracker for peer-review, and need two acknowledgments from team members before being published. <br />
<br />
The [https://security.archlinux.org/ Arch Linux security tracker] is a platform used by the Arch Security Team to track packages, add CVEs and generate advisory text. <br />
<br />
{{Note|<br />
* An ''Arch Linux Vulnerability Group'' (AVG) is a group of CVEs related to a set of packages within the same ''pkgbase''.<br />
* Packages qualified for an advisory must be part of the ''core'', ''extra'', ''community'' or ''multilib'' repository.<br />
}}<br />
<br />
== Contribute ==<br />
<br />
To get involved in the identification of the vulnerabilities, it is recommended to:<br />
<br />
* Follow the [irc://irc.freenode.net/archlinux-security #archlinux-security] IRC channel. It is the main communication medium for reporting and discussing CVEs, packages affected and first fixed package version.<br />
* In order to be warned early about new issues, one can monitor the recommended [[#Mailing lists]] for new CVEs, along with other sources if required. <br />
* We encourage volunteers to look over the advisories for mistakes, questions, or comments and report in the IRC channel.<br />
* Subscribe to the mailing lists [https://lists.archlinux.org/listinfo/arch-security arch-security] and [http://oss-security.openwall.org/wiki/mailing-lists/oss-security oss-security].<br />
* Committing code to the [https://github.com/archlinux/arch-security-tracker arch-security-tracker (GitHub)] project is a great way to contribute to the team.<br />
* Derivative distributions that rely on Arch Linux package repositories are encouraged to contribute. This helps the security of all the users.<br />
<br />
== Procedure ==<br />
<br />
The procedure to follow whenever a security vulnerability has been found in a software packaged within the Arch Linux official repositories is the following:<br />
<br />
=== Information sharing and investigation phase ===<br />
<br />
* Reach out an Arch Security Team member via your preferred channel to ensure the issue has been brought to the attention of the team.<br />
* In order to substantiate the vulnerability, verify the CVE report against the current package version (including possible patches), and collect as much information as possible on the issue, including via search engines. If you need help to investigate the security issue, ask for advice or support on the IRC channel.<br />
<br />
=== Upstream situation and bug reporting ===<br />
<br />
Two situations may arise:<br />
<br />
* If upstream released a new version that fixes the issue, the Security Team member should flag the package out-of-date.<br />
** If the package has not been updated after a long delay, a bug report should be filed about the vulnerability.<br />
** If this is a critical security issue, a bug report must be filed immediately after flagging the package out-of-date.<br />
* If there is no upstream release available, a bug report must be filed including the patches for mitigation. The following information must be provided in the bug report:<br />
** Description about the security issue and its impact<br />
** Links to the CVE-IDs and (upstream) report<br />
** If no release is available, links to the upstream patches (or attachments) that mitigate the issue<br />
<br />
=== Tracking and publishing ===<br />
<br />
The following tasks must be performed by team members:<br />
<br />
* A team member will create an advisory on the [https://security.archlinux.org/ security tracker] and add the CVEs for tracking.<br />
* A team member with access to [https://lists.archlinux.org/listinfo/arch-security arch-security] will generate an ASA from the tracker and publish it.<br />
<br />
{{Note|If you have a private bug to report, contact [https://mailman.archlinux.org/pipermail/arch-security/2014-June/000088.html security@archlinux.org]. Please note that the address for private bug reporting is ''security'', not ''arch-security''. A private bug is one that is too sensitive to post where anyone can read and exploit it, e.g. vulnerabilities in the Arch Linux infrastructure.}}<br />
<br />
== Resources ==<br />
<br />
=== RSS ===<br />
<br />
; National Vulnerability Database (NVD)<br />
: All CVE vulnerabilites: https://nvd.nist.gov/download/nvd-rss.xml<br />
: All fully analyzed CVE vulnerabilities: https://nvd.nist.gov/download/nvd-rss-analyzed.xml<br />
<br />
=== Mailing lists ===<br />
<br />
; oss-sec: Main list dealing with security of free software, a lot of CVE attributions happen here, required if you wish to follow security news.<br />
: Info: http://oss-security.openwall.org/wiki/mailing-lists/oss-security<br />
: Subscribe: oss-security-subscribe(at)lists.openwall.com<br />
: Archive: http://www.openwall.com/lists/oss-security/<br />
<br />
; BugTraq: A full disclosure moderated mailing list (noisy).<br />
: Info: http://www.securityfocus.com/archive/1/description<br />
: Subscribe: bugtraq-subscribe(at)securityfocus.com<br />
<br />
; Full-disclosure: Another full-disclosure mailing-list (noisy).<br />
: Info: http://lists.grok.org.uk/full-disclosure-charter.html<br />
: Subscribe: full-disclosure-request(at)lists.grok.org.uk<br />
<br />
Also consider following the mailing lists for specific packages, such as LibreOffice, X.org, Puppetlabs, ISC, etc.<br />
<br />
=== Other distributions ===<br />
<br />
Resources of other distributions (to look for CVE, patch, comments etc.):<br />
<br />
; RedHat and Fedora:<br />
: Advisories feed: https://bodhi.fedoraproject.org/rss/updates/?type=security<br />
: CVE tracker: https://access.redhat.com/security/cve/<CVE-ID><br />
: Bug tracker: https://bugzilla.redhat.com/show_bug.cgi?id=<CVE-ID><br />
<br />
; Ubuntu:<br />
: Advisories feed: https://usn.ubuntu.com/usn/atom.xml<br />
: CVE tracker: https://people.canonical.com/~ubuntu-security/cve/?cve=<CVE-ID><br />
: Database: https://code.launchpad.net/~ubuntu-security/ubuntu-cve-tracker/master<br />
<br />
; Debian:<br />
: CVE tracker: https://security-tracker.debian.org/tracker/<CVE-ID>/<br />
: Patch tracker: https://tracker.debian.org/pkg/patch<br />
: Database: https://anonscm.debian.org/viewvc/secure-testing/data/<br />
<br />
; OpenSUSE:<br />
: CVE tracker: https://www.suse.com/security/cve/<CVE-ID>/<br />
<br />
=== Other ===<br />
<br />
; Mitre and NVD links for CVE's:<br />
: https://cve.mitre.org/cgi-bin/cvename.cgi?name=<CVE-ID><br />
: https://web.nvd.nist.gov/view/vuln/detail?vulnId=<CVE-ID><br />
<br />
NVD and Mitre do not necessarily fill their CVE entry immediately after attribution, so it is not always relevant for Arch. The CVE-ID and the "Date Entry Created" fields do not have particular meaning. CVE are attributed by CVE Numbering Authorities (CNA), and each CNA obtain CVE blocks from Mitre when needed/asked, so the CVE ID is not linked to the attribution date. The "Date Entry Created" field often only indicates when the CVE block was given to the CNA, nothing more.<br />
<br />
; Linux Weekly News: LWN provides a daily notice of security updates for various distributions.<br />
: https://lwn.net/headlines/newrss<br />
<br />
=== More ===<br />
<br />
For more resources, please see the OpenWall's [http://oss-security.openwall.org/wiki/ Open Source Software Security Wiki].<br />
<br />
== Team members ==<br />
<br />
The current members of the Arch Security Team are:<br />
<br />
* [[User:anthraxx|Levente Polyak]]<br />
* [[User:rgacogne|Remi Gacogne]]<br />
* [[User:Shibumi|Christian Rebischke]]<br />
* [[User:Jelly|Jelle van der Waa]]<br />
* [[User:Sangy|Santiago Torres-Arias]]<br />
* [[User:pid1|Jonathan Roemer]]<br />
* [[User:Foxboron|Morten Linderud]]<br />
<br />
{{Note|Run {{ic|!pingsec <msg>}} in [[IRC channels]] to highlight all current security team members.}}</div>2114L3