Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
How not to respond to a security advisory
Jason Miller, 2006-01-18

A recently announced weakness in the BSD securelevel system isn't going to be fixed in OpenBSD. While securelevel may have problems, the vendor's security response is unacceptable and doesn't fit with their stated goals.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
Re: How not to respond to a security advisory 2006-01-25
Matthew Murphy
Why does Jason need to include "formal input from the OpenBSD team"? He has it, in the form of the comment from Theo De Raadt.

OpenBSD didn't choose to "let it die on the vine" (it still ships, vulnerability-and-all). They just aren't fixing it because it's one less security bug for them to adm...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus