The brk() vulnerability
Posted Dec 2, 2003 20:21 UTC (Tue) by
elanthis (subscriber, #6227)
In reply to:
The brk() vulnerability by beejaybee
Parent article:
The brk() vulnerability
This isn't really true. It's similar to how bugtraq and other security organizations give companies time to release fixed software before the announcement of the vulnerability is even made - the fix exists and users can download it, and have had ample time to do so, before most attackers even know there is a hole.
With the open nature of the kernel developement, the "announcement" is out there before anyone but a few kernel developers have a chance to so much as know the patch exists.
Some good policy on keeping security fixes "secret" until after they're in a release (or at least -pre patch), and then keeping the details secret until the fix has been out for a while, could solve this problem. *could*.
(
Log in to post comments)