Re: Complicated Disclosure Scenario

From: Mariusz Mazur (
Date: 01/17/02

Date: Thu, 17 Jan 2002 18:36:05 +0100
From: Mariusz Mazur <>
To: Josha Bronson <>

On 2002-01-17 Josha Bronson wrote the folowyng:

JB> This is the problem as it sits. If I reach out to "the community" for
JB> additional assistance with researching this bug I might as well just send
JB> out an advisory. If I release an advisory the vendor will most likely
JB> not have a patch ready, they will feel violated and the user base will
JB> be left open to exploitation with no fix. If I do nothing, the problem
JB> persists and nothing gets accomplished, and maybe someone with not so
JB> good intentions discovers the same bug and uses it to do harm.

JB> So, what would you do?

Well. "The community" doesn't have to be vuln-dev. Pick a couple of
known sec teams and ask them if they have the will and proper equipment
to check wether this thing is exploitable. I'm sure you'll find at least
one willing to take it over from you.

Mariusz Mazur
"One Ring to bring them all and in the darkness bind them"

Relevant Pages

  • Re: new daylight savings time
    ... I kind of like the vibrancy of the Ubuntu community: ... Developers and testers are *part* of an eco-system which is ultimately ... What good would it do anyone to have a bug report for FC4 coming in now ... any particular distribution or version, they just keep fixing and adding ...
  • RE: Whitebox Linux
    ... SRPMS has been provided and updated. ... > Linux, and that bug doesn't get fixed in a RHEL update, and the Whitebox ... I worry about the support from whitebox community. ...
  • Re: Das richtige Framework
    ... einen Bug, einen gravierenden Bug. ... das Problem durch die Community schnell behoben wird bzw. (bei ... Dipl.Inf. Frank Dzaebel ...
  • Re: Licences
    ... and contribute their fix to "the community". ... I filed a bug in the Debian bug tracking system, ... The moral of the story is this: if you find a bug in GNAT, report it. ...
  • Re: Mandrake 10.0 Official vs Community
    ... > I just got back into linux Mandrake and have been using it for a ... > community, ... Does that mean if I did the of bug fixes I am ok ... Community was a download only edition launched ahead of the Official ...