[11197] in bugtraq

home help back first fref pref prev next nref lref last post

Re: [linux-security] [RHSA-1999:023-01] Potential security

daemon@ATHENA.MIT.EDU (David Schwartz)
Fri Jul 30 18:57:13 1999

Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Message-Id:  <000701bedaa1$302d7d70$021d85d1@youwant.to>
Date:         Fri, 30 Jul 1999 08:35:44 -0700
Reply-To: David Schwartz <davids@WEBMASTER.COM>
From: David Schwartz <davids@WEBMASTER.COM>
X-To:         Miguel de Icaza <miguel@gnu.org>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <199907292356.SAA27035@erandi.nuclecu.unam.mx>

> > > Give people a chance to upgrade Gnumeric and I will happilly share the
> > > information with bugtraq (if someone does not read the 10 diffs in the
> > > meantime).
> >
> > 	  I understand your intentions, but I don't think they make
> any sense.
>
> I do not understand what do you mean.  Why do you say it does not make
> sense to try (only try) to protect users by not disclosing the
> information now?

	Because the way you have left things, only those most strongly motivated to
determine the exploit will know it. Those most strongly motivated to
determine it are those who would exploit it. And you've left the users in
the dark.

> You can trust me in the meantime.  Hey, if you are running Gnumeric
> currently you are already trusting me ;-)

	It's not a matter of trusting you. It's a matter of having sufficient
information to determine whether this exploit warrants an immediate upgrade.

> I will disclose all information after people have had a chance to
> upgrade their Gnumerics.

	Yes, but those who wish to exploit the defect will already know it. You've
given the bad guys a lead on the good guys.

	DS

home help back first fref pref prev next nref lref last post