LWN.net Logo

Then this vulnerability was only published because it was "spoiled goods"?

Then this vulnerability was only published because it was "spoiled goods"?

Posted Jul 20, 2009 5:38 UTC (Mon) by khim (subscriber, #9252)
In reply to: Linux 2.6.30 exploit posted by spender
Parent article: Linux 2.6.30 exploit posted

Customers of that legitimate purchaser get a copies of fully- working exploits (not PoCs) for vulnerabilities that are unfixed.

Does it mean that vulnerabilities like discussed one are only ever disclosed when they can not be sold? This time fix was introduced before the exploit (sure it was not included in -stable relase, but it was in git-head already), so it was impossible to sell it to "legitimate purchaser"?


(Log in to post comments)

Then this vulnerability was only published because it was "spoiled goods"?

Posted Jul 20, 2009 11:20 UTC (Mon) by nix (subscriber, #2304) [Link]

Well, since he just said elsewhere in this thread that's he's going to start selling RH vulnerabilities, one must assume the answer, this time, was no, but in future will be yes.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds