Full Disclosure mailing list archives

Microsoft credit policy (was: EEYE: Microsoft ASN.1 Library Length Overflow Heap Corruption)


From: Spiro Trikaliotis <trik-news () gmx de>
Date: Wed, 11 Feb 2004 18:45:39 +0100

Hello,

* On Wed, Feb 11, 2004 at 01:02:30PM +0800 Benjamin Meade wrote:

Link: http://www.eeye.com/html/Research/Upcoming/index.html 

Given this, couldn't they (eEye) at least release basic details and a 
workaround?

No, they cannot. If they did, MS would not give them credit on this
discovery:

   http://www.microsoft.com/technet/security/bulletin/policy.asp

Isn't it a good advertisement to be mentioned in Microsoft's Knowledge
Base?

Just my 2 cent worth,
   Spiro.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: