[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Cobalt Wish List



Chris Adams wrote:

> Well, you should first notify a vendor about a problem and give them a
> reasonable amount of time to produce a fix before sending it to BUGTRAQ.

What's "reasonable amount of time" when it's a security issue <smile>?

> That's what I did with the cgiwrap security problem a while back,
> although I didn't get a fix until after I posted to BUGTRAQ.

See what I mean <smile, again>?

Jeff
-- 
Jeff Lasman <jblists@xxxxxxxxxxxxx>
nobaloney.net
P. O. Box 52672
Riverside, CA  92517
voice: (909) 787-8589  *  fax: (909) 782-0205