BugTraq
Misinformation in Security Advisories (ASN.1) Feb 16 2004 05:47PM
John Compton (john_compton24 yahoo com) (4 replies)
Re: Misinformation in Security Advisories (ASN.1) Feb 17 2004 03:10PM
Slawek (sgp telsatgp com pl)
Re: Misinformation in Security Advisories (ASN.1) Feb 16 2004 09:45PM
Ivan Arce (ivan arce coresecurity com)
Re: Misinformation in Security Advisories (ASN.1) Feb 16 2004 07:57PM
evol ruiner halo nu
Re: Misinformation in Security Advisories (ASN.1) Feb 16 2004 07:35PM
Simon Brady (simon brady otago ac nz) (1 replies)
On Mon, 16 Feb 2004, John Compton wrote:

> First of all, there is good news for those of you out there who are
> worried about the new ASN.1 vulnerability in Microsoft operating
> systems. It is NOT exploitable to run arbitrary code in anything
> approaching a real-world scenario.

With all due respect, doesn't your argument for this claim boil down to "I
can't see a way to exploit it therefore it can't be exploitable?". This is
hardly a compelling case for sysadmins not to patch, particularly when
we're hearing other self-proclaimed experts contradicting your claim.

Maybe you're right, but I would be professionally negligent to leave my
employer's systems unpatched based on the case you've presented. My job is
to minimise risk to our operations and maximise confidence in the
integrity of our systems: I'm not about to wait to be compromised so I can
say "oh look, it was exploitable after all - I guess patching is justified
now".

Like it or not, our line of work is all about dealing with uncertainty and
making tough calls based on insufficient evidence. I too would like to see
a single, clearly authoritative advisory on any given security issue, but
that doesn't seem likely out here in the real world.

--
Simon Brady mailto:simon.brady (at) otago.ac (dot) nz [email concealed]
ITS Technical Services
University of Otago, Dunedin, New Zealand

[ reply ]
Re: Misinformation in Security Advisories (ASN.1) Feb 17 2004 12:17AM
Anthony Saffer (anthonysaffer yahoo com)


 

Privacy Statement
Copyright 2010, SecurityFocus