lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Tue, 28 Apr 2009 14:17:34 +0300 (EEST)
From: Juha-Matti Laurio <juha-matti.laurio@...ti.fi>
To: full-disclosure@...ts.grok.org.uk, sunjester <tripmonster@...il.com>
Subject: Re: full disclosure?

If posting to CVE and NVD handlers at the same time it's a good advice to use BCC...

Juha-Matti

sunjester [tripmonster@...il.com] wrote: 
> this is in regards to...
> 
> Message: 1
> > Date: Mon, 27 Apr 2009 16:39:32 +0200
> > From: Thierry Zoller <Thierry@...ler.lu>
> > Subject: [Full-disclosure] [TZO-13-2009] Avira Antivir generic CAB
> >        evasion /       bypass
> > To: NTBUGTRAQ <NTBUGTRAQ@...TSERV.NTBUGTRAQ.COM>,       bugtraq
> >        <bugtraq@...urityfocus.com>,    full-disclosure
> >        <full-disclosure@...ts.grok.org.uk>, <info@...cl.etat.lu>,
> >        <vuln@...unia.com>, <cert@...t.org>, <nvd@...t.gov>, <cve@...re.org
> > >
> > Message-ID: <564846161.20090427163932@...ler.lu>
> > Content-Type: text/plain; charset=iso-8859-15
> >
> > ______________________________________________________________________
> >
> >  From the low-hanging-fruit-department - Avira antivir bypass/evasion
> > ______________________________________________________________________
> >
> > Release mode: Coordinated but limited disclosure.
> > Ref         : TZO-132009 - Avira Antivir evasion CAB
> > WWW         :
> > http://blog.zoller.lu/2009/04/avira-antivir-generic-cab-bypass.html
> > Vendor      : http://www.avira.com
> > Status      : Patched
> > Security notification reaction rating : Good
> > Notification to patch window : 7 days (Eastern holidays in between)
> >
> > Disclosure Policy :
> > http://blog.zoller.lu/2008/09/notification-and-disclosure-policy.html
> >
> 
> there is no disclosure at all for this? am i missing the meaning of "full
> disclosure" ?
> 
> -- 
> Lerie Taylor
> Lead Developer, Skin Care Heaven
> http://www.skincareheaven.com/
> 

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists