Dailydave mailing list archives

Re: A really bad month for Novell


From: "Steven M. Christey" <coley () mitre org>
Date: Thu, 7 Dec 2006 17:23:12 -0500 (EST)


"Anton Chuvakin" <anton () chuvakin org> said:

Wow, did something happen in the world and I totally missed it? Is
this what they call a "best practice" (yak!) now...? 1 year and 3
months to report a vuln to a vendor...

You sometimes see these kinds of tidbits in iDEFENSE advisories, too.
I'm not sure of the reason for it, although maybe there's a delay
while they verify if the issue is real, and/or figure out who to
notify at the vendor.  Which I know many researchers can relate to :)

- Steve
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: