[Full-Disclosure] Silent Fixes (was GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution)

From: Leif Sawyer (lsawyer_at_gci.com)
Date: 02/18/04

  • Next message: Ulf Härnhammar: "[Full-Disclosure] metamail format string bugs and buffer overflows"
    To: full-disclosure@lists.netsys.com
    Date: Wed, 18 Feb 2004 11:40:57 -0900
    
    

    gabriel rosenkoetter writes:
    > Oh, give me a break. Some developer went, "Oh, hey, I'm not
    > bounds checking there. Okay, fix that," and the changes
    > filtered out into the release of IE.
    > [... blah blah ...] Hell, do we expect Linux or NetBSD
    > [ to tell us about every buffer overflow they fix? ]

    Uh. Methinks you don't read the linux kernel mailing list,
    do you?

    Yes, every freaking buffer overflow they fix is discussed.
    In fact, nearly every change made to the kernel is discussed
    at some point. And it's all documented as to whom the person
    was what inserted the code in the first place, and who fixed it.

    Responsible? Check.
    Open? Check.
    The way it _should_ be? Check.

    Caveat: I don't subscribe to any BSD lists, but I can infer that
     they have a similar process in place.

    Silent fixes suck. The only thing they do is prevent the user
    from making an informed decision about how to deal with them.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Ulf Härnhammar: "[Full-Disclosure] metamail format string bugs and buffer overflows"

    Relevant Pages

    • RE: [Full-Disclosure] Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution
      ... Some developer went, "Oh, hey, I'm not bounds ... Okay, fix that," and the changes filtered out into ... web browser as 'intensely performance critical'; ...
      (Full-Disclosure)
    • Re: Fix up power managment in 2.6
      ... That is, until the latest round of patches, in which the ... Okay, my point was that the patch was not exactly obvious. ... Trying to fix error handling is good and welcome, ...
      (Linux-Kernel)
    • Re: Ted Kennedy A Sneaky Mother Fucker.
      ... Let's provide except the profitable piers, ... fix the dull evidences. ... Hey, it wounds a partner too nice toward her ...
      (sci.lang)
    • Re: To Context switch or Spin
      ... easily tested fix for the final few months of the products ... // okay, no worries, we can do other work.in another thread ... I did not realize that your Boss was making those type of requirements. ... life is life; fun times indeed! ...
      (comp.programming.threads)
    • Re: Word Exploit and Word 97
      ... Okay, let's look at this in the real world now. ... >What I DO expect from Microsoft...is that a MAJOR flaw in ... >I think Microsoft would make a LOT of brownie points by ... >and if Microsoft doesn't fix the problem in Word 97... ...
      (microsoft.public.security)

  • Quantcast