Re: Huge security hole in Kerio 2.1.5

From: Hassan I Sahba (me_at_privacy.net)
Date: 03/07/05


Date: Sun, 06 Mar 2005 23:14:02 +0000

On Sun, 06 Mar 2005 21:34:06 GMT, Duane Arnold <notme@notme.com>
wrote:
<snip>

>And what did the vendor tell you about what they were going to do about
>the situation? I think they indicated that the product was not being
>supported and they were NOT going to do anything about it. The vendor
>doesn't care about it.

Exactly. Why can't they tell people to stop using it. Because that
would mean admitting it was vulnerable for years? People are
forgetting this is a 6 year old vulnerability. It wasn't fixed, fair
enough, it was free. It wasn't announced, not good enough.

> And I don't think it's going to hurt their reputation about a product they no
>longer support one bit.

Too late.

> In other words, it's a *moot* point. The vendor has moved on to a new
>product they >are now supporting and Kerio 2.15 is *dead* as far as the
> vendor is concerned.
>
>Duane :)

HiS



Relevant Pages


Quantcast