[25916] in bugtraq
Re: ISS Apache Advisory Response
daemon@ATHENA.MIT.EDU (Mike Eldridge)
Fri Jun 21 19:42:43 2002
Date: Fri, 21 Jun 2002 18:23:30 -0500
From: Mike Eldridge <diz@cafes.net>
To: bugtraq@securityfocus.com
Message-ID: <20020621182330.C24902@ornery.cafes.net>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <F3E7C024F0FD4E44BC78DB62CEBC16135682@atlmaiexcp02.iss.local>; from CKlaus@iss.net on Thu, Jun 20, 2002 at 06:06:03PM -0400
On Thu, Jun 20, 2002 at 06:06:03PM -0400, Klaus, Chris (ISSAtlanta) wrote:
> There has been a lot of misinformation spread about our ISS Apache Advisory
> and wanted to clean up any confusion and misunderstanding.
>
> 1) Our policy for publishing advisories is to give a vendor 30 to 45
> day quiet period to provide an opportunity to create a patch or work around.
> If an exploit for the vulnerability appears in the wild, or a patch and
> work-around is provided by the vendor or ISS X-Force, this quiet period is
> disregarded and the ISS X-Force advisory is published immediately.
>
> In the case of this advisory, ISS X-Force provided an Apache patch and did
> not see a need for a long quiet period.
this is a poor justification and is showing extreme disrespect to the
apache project.
if there was a hole in my software package abc, responsibility for
closing the hole is up to *me*, not you. i would find it extremely
disrespectful and irresponsible if you released an advisory and provided
your *own* patch for it, no matter if it closed the hole or not.
what if your patch caused more problems than it fixed, which is possible
since it's extremely doubtful that you would have more intimate
knowledge of the project than the principal developers do.
the responsibility is the developers', not yours.
-mike
------------------------------------------------------------------------
/~\ the ascii subvert the dominant paradigm
\ / ribbon campaign
X against html
/ \ email!