Re: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability
- From: Peter Besenbruch <prb@xxxxxxxx>
- Date: Fri, 28 Apr 2006 06:36:01 -1000
On Thu, 27 Apr 2006, Brian Eaton wrote:
Please note that I ask this out of curiousity, and not in an attempt to
be critical. Why not give MSRC a head start of one week?
Michal Zalewski wrote:
Because, among other things I've already mentioned, it will in no way
affect when they're going to release a patch. Their official policy is to
stick to a weird schedule.
Unfortunately, given Microsoft's recent behavior, Michal's right. Further, I too have seen the data showing much faster response times when Microsoft is blindsided. The only question that remains is whether some inherent sense of fairness on the part of the reporter dictates notifying the vendor first, even though it likely won't do any good.
--
Hawaiian Astronomical Society: http://www.hawastsoc.org
HAS Deepsky Atlas: http://www.hawastsoc.org/deepsky
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- Follow-Ups:
- RE: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability
- From: Chris Eagle
- RE: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability
- References:
- RE: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability
- From: Tim Bilbro
- RE: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability
- From: Michal Zalewski
- Re: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability
- From: Brian Eaton
- Re: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability
- From: Michal Zalewski
- RE: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability
- Prev by Date: Re: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability
- Next by Date: [Full-disclosure] [Argeniss] Alert - Yahoo! Mail XSS vulnerability
- Previous by thread: Re: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability
- Next by thread: RE: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability
- Index(es):
Relevant Pages
|