oss-sec mailing list archives

Re: CVE request - Linux kernel: VFAT slab-based buffer overflow


From: Tim <tim-security () sentinelchicken org>
Date: Wed, 27 Feb 2013 11:36:32 -0800



Hmm, I wonder if perhaps the solution here isn't about spending a lot
of time analyzing hundreds of potentially serious bugs and notifying
the world about them all in an accurate way.  Perhaps the solution is
changing the development model or architecture of the kernel such that
there aren't so many bugs with *serious* impact in the first place.

Ooops... did I say that out loud?  

Seriously though, when threads of disagreement erupt like this, often
taking a step back to look at the root cause is a good approach.

tim


Current thread: