vulnerability disclosure policies
Posted Dec 17, 2004 10:37 UTC (Fri) by
DonDiego (subscriber, #24141)
Parent article:
Students uncover dozens of Unix software flaws (News.com)
Whatever happened to informing authors/vendors of vulnerabilities first and giving them some time to patch the application before making issues public? I work on MPlayer and we were not informed prior to making the vulnerability public, a mail was sent to our users mailing list (not even the developers mailing list) at the same time it was sent out to the world. Irresponsible behavior IMNSHO.
(
Log in to post comments)