Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Vulnerability Disclosure

Vulnerability Disclosure

From: <matt.steer_at_marstons.co.uk>
Date: 5 Jun 2007 03:52:13 -0000
('binary' encoding is not supported, stored as-is) Hi Guys,

I have been playing around with a program and have discovered a bug that I have successfully leveraged into code execution. I reported my findings to the vendor, not yet receiving a reply; this is the first time I have done this.

The bug is in an installer and malicious input is crafted then pasted into an input field which is copied into a buffer of insufficient size. The conditions of the exploit seem a little extreme to me, but it still results in code execution.

The fact that it is in an installer, hence most likely requiring Admin rights, and is a local exploit the risk of this vulnerability being exploited seems low (too me, not being a risk assessor!) .

This brings me to my question;

Should all vulnerabilities be disclosed to a vendor (at least!) however high or low risk?

I’ve never been a believer in ‘Security through Obscurity’, but do the people think there comes a point when it may just be a waste of time?

To be honest; I hope not!

Matthew Steer
Received on Jun 06 2007

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos