Re: [linux-security] [RHSA-1999:023-01] Potential security

From: David Schwartz (davidsat_private)
Date: Fri Jul 30 1999 - 08:35:44 PDT

  • Next message: David Taylor: "Re: Simple DOS attack on FW-1"

    > > > Give people a chance to upgrade Gnumeric and I will happilly share the
    > > > information with bugtraq (if someone does not read the 10 diffs in the
    > > > meantime).
    > >
    > > 	  I understand your intentions, but I don't think they make
    > any sense.
    >
    > I do not understand what do you mean.  Why do you say it does not make
    > sense to try (only try) to protect users by not disclosing the
    > information now?
    
    	Because the way you have left things, only those most strongly motivated to
    determine the exploit will know it. Those most strongly motivated to
    determine it are those who would exploit it. And you've left the users in
    the dark.
    
    > You can trust me in the meantime.  Hey, if you are running Gnumeric
    > currently you are already trusting me ;-)
    
    	It's not a matter of trusting you. It's a matter of having sufficient
    information to determine whether this exploit warrants an immediate upgrade.
    
    > I will disclose all information after people have had a chance to
    > upgrade their Gnumerics.
    
    	Yes, but those who wish to exploit the defect will already know it. You've
    given the bad guys a lead on the good guys.
    
    	DS
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:54:16 PDT