[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] BugTraq



> > Why do you see bugtraq as a last resort?  I've always
> > considered it a first resort.
>
> Well, you should first notify a vendor about a problem and give them a
> reasonable amount of time to produce a fix before sending it
> to BUGTRAQ.
> That's what I did with the cgiwrap security problem a while back,
> although I didn't get a fix until after I posted to BUGTRAQ.

However, Chris, when someone finds such an issue, notifying BugTraq ASAP
lets the rest of us know it's there while the vendor has a reasonable time
to fix it. That way we can live with it, or shut it down, or something, in
the meantime.

------
Rodolfo J. Paiz
rpaiz@xxxxxxxxxxxxxx <mailto:rpaiz@xxxxxxxxxxxxxx>