oss-sec mailing list archives
Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser
From: Leif Nixon <nixon () lysator liu se>
Date: Fri, 24 Jul 2015 11:47:31 +0200
Philip Pettersson <philip.pettersson () gmail com> writes:
On Fri, Jul 24, 2015 at 3:43 AM, Leif Nixon <nixon () lysator liu se> wrote:Qualys Security Advisory <qsa () qualys com> writes:Hello, it is July 23, 2015, 17:00 UTC, the Coordinated Release Date for CVE-2015-3245 and CVE-2015-3246. Please find our advisory below, and our exploit attached.*Why* are you releasing a full exploit just minutes after the patch is released? (Disclosure: I am employed by Red Hat, but this is my purely personal question.)That's how coordinated release dates work. Instead of trying to shame Qualys for not following your arbitrary views on what is and isn't "Responsible Disclosure", perhaps you should make sure Red Hat releases patches hours before the CRD, like Ubuntu does?
Oh, hi there. My views are not very arbitrary; rather they are based on years of trying to defend big infrastructures. As I see it, there are two reasons for releasing working exploits without warning; 1) Forcing the hand of a non-responsive vendor, 2) Stroking a weak ego by showing off. (Or for marketing, but that comes to the same thing.) Except for case 1, releasing a working exploit *does not help anybody* except the kiddies. If there are other reasons, I'd like to be told about them. If Qualys had released a slightly less detailed advisory, or even just left off the actual exploit, and given users a day or two to patch their systems before going full disclosure, the risk to innocent bystanders would have been much reduced. -- Leif Nixon ------------------------------------------------------------------------------ "supercomputer specialists are charming, polite [and] witty" -- Wired Magazine ------------------------------------------------------------------------------
Current thread:
- Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Qualys Security Advisory (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Leif Nixon (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Philip Pettersson (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Jamie Strandboge (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Kurt Seifried (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Leif Nixon (Jul 24)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Martino Dell'Ambrogio (Jul 24)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Joshua Rogers (Jul 24)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Leif Nixon (Jul 24)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Brad Knowles (Jul 24)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Leif Nixon (Jul 25)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Michal Zalewski (Jul 25)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Dave Horsfall (Jul 25)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Brad Knowles (Jul 25)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Hanno Böck (Jul 26)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Philip Pettersson (Jul 23)
- Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser Leif Nixon (Jul 23)