lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
From: coley at mitre.org (Steven M. Christey)
Subject: mnogosearch 3.1.20 and 3.2.10 buffer overflow

>> Vendor has been contacted on 01/06/2003 and fix is available from cvs at
>> http://www.mnogosearch.org.
>>
>------------ end snippy -----------
>
> 5 months...  This is full disclosure?

Maybe that date is really June 1, 2003, since many countries list the
month second, not first.

By the way, these DD/MM/YYYY or MM/DD/YYYY formats often make it
difficult to quantify how much notice a vendor really had before the
issue was published.  This has affected the accuracy of my past
aborted attempts to figure out how long vendors *really* take to fix
issues, and it may hamper any future attempts.

Using formats like YYYY/MM/DD or "Month DD, YYYY" generally seems to
address the confusion.

- Steve

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ