A second remote hole for OpenBSD
Posted Mar 14, 2007 17:15 UTC (Wed) by
ajross (subscriber, #4563)
Parent article:
A second remote hole for OpenBSD
I have to wonder if that "Only N remote holes" marketing tactic is
doing more harm than good. Inevitably, it leads to the kind of
semantic games we see here: a verified buffer overflow and kernel
crash (which is always, almost by definition, a potential remote code
execution vulnerability until it can be proven unexploitable) was only termed a non-security DoS issue
until CORE came up with an actual exploit.
One has to wonder if the psychological difficulty of bumping that
"Only N" count made the OpenBSD team less receptive to this bug report
than they otherwise might have been. But they did fix the bug, and
they did, ultimately, increment N. So all's well that ends well, I
guess.
(
Log in to post comments)