let's not forget, this is only alpha code. it is a good thing that the vuln was found and reported to ibm. i think the advisory is more than appropriate given that this is most likely not being used in production by anyone. i don't know much about alphaworks but i would presume that all code comes with a caveat that it could be buggy. sean -----Original Message----- From: John Schultz [mailto:jschultzat_private] Sent: Saturday, July 21, 2001 3:36 PM To: bugtraqat_private Subject: Re: IBM TFTP Server for Java vulnerability On Fri, 20 Jul 2001, Patrick Medhurst wrote: > The vendor was contacted on 19 June 2001 and responded on 20 June 2001 > as follows: > "We will take a look at the issue and fix it as soon as possible". > > Further correspondence requesting when a fix will be released has been > ignored. Just because a company can't tell you immediately when a bug will be fixed, you say that you are being ignored and see fit to release an advisory? Do you have any idea how easy the problem will be to fix? Probably not, and I bet IBM would have to do some research first, finding out what code contains the problem, allocating developers, build personnel, and QA the fix before even they know when a fix will be out. Sheesh. John Schultz jschultzat_private
This archive was generated by hypermail 2b30 : Mon Jul 23 2001 - 10:43:34 PDT