Full Disclosure mailing list archives
Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution
From: Tim <tim-security () sentinelchicken org>
Date: Wed, 18 Feb 2004 09:12:59 -0800
Oh, give me a break. Some developer went, "Oh, hey, I'm not bounds checking there. Okay, fix that," and the changes filtered out into the release of IE. You don't release "security patches" except in response to publication of a serious vulnerability, and especially in response to a problem that's systemic. This is *a* buffer overflow. Do we expect even Sun or Apple to tell us about every buffer overflow they fix? Hell, do we expect Linux or NetBSD to do so? C'mon, people. If you're going to be quoted for publication, try to make statements reasonable to the actual importance of the issues at hand.
Say you are an engineer at a large car manufacturing company. Suppose, 6 months after the 2004 model of your sedan goes out the door, you discover, as an engineer who helped build it, that the car's frame is flawed. Suppose that it is so flawed that after 3 years, it may break due to normal use, potentially causing bad crashes. Is it your moral obligation to notify customers? Sure you are going to fix it in next year's model, that is a given. But what about all those people with a potentially deadly model? Obviously, this is not the auto industry. Some will argue that we are not talking about life-and-death situations here. But the reality is, we are. Software bugs can cause death, and have before, both on the small scale, and the large scale. (can you say "power outage"?) As the world moves forward with "progress", it will become ever more important. It is about time that IT professionals realize this and start expecting quality out of the products they buy. Hope that puts it into perspective for some people. tim _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution, (continued)
- Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution KF (Feb 15)
- Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution morning_wood (Feb 15)
- Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution KF (Feb 15)
- Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution morning_wood (Feb 15)
- Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution Byron Copeland (Feb 15)
- RE: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution Aditya, ALD [Aditya Lalit Deshmukh] (Feb 16)
- Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution morning_wood (Feb 17)
- Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution gabriel rosenkoetter (Feb 18)
- Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution Dave Sherohman (Feb 18)
- RE: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution Steve Wray (Feb 18)
- Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution Tim (Feb 18)
- Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution gabriel rosenkoetter (Feb 18)
- Re: Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution Tim (Feb 18)
- Re: Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution insecure (Feb 18)
- RE: Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution Bill Royds (Feb 18)
- Re: Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution Phil Brutsche (Feb 18)
- RE: Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution Paul Schmehl (Feb 18)
- Re: Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution morning_wood (Feb 18)
- Re: Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution Paul Schmehl (Feb 18)
- Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution morning_wood (Feb 15)
- RE: Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution Byron Copeland (Feb 18)
- Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution KF (Feb 15)
- Re: Re: Re: GAYER THAN AIDS ADVISORY #01: IE 5 remote code execution morning_wood (Feb 18)