[VulnDiscuss] CAN-2003-0552 (and advisory quality)

Florian Weimer <[email protected]> Mon, 28 Jul 2003 22:44:51 +0200
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
You might have noticed the following paragraph in the Red Hat
advisory:

| CAN-2003-0552: Jerry Kreuscher discovered that the Forwarding table
| could be spoofed by sending forged packets with bogus source
| addresses the same as the local host.

This looks pretty scary at first sight, but is apparently relevant to
bridges (not routers), see Herbert Xu's message in:

<http://lists.debian.org/debian-security/2003/debian-security-200307/msg00140.html>

So it's not a big problem.  But better check it yourself, you know the
drill: get the SRPM, pipe it through rpm2cpio, and look at the diffs
with the most recent date -- as usual.

Anyway, this is a fine example that currently, large parts of the Free
Software community cannot resolve security issues in a reasonable
manner.  Just compare Red Hat's patch availability notice (it's
nothing more than that) to one of the more recent Microsoft
advisories.  You know something is wrong if Microsoft, the leader in
the movement to end information security "anarchy", is offering much
more detailed information than the competition.

Apparently, few companies are willing to face the legal risk of
spreading misinformation in advisories, as such risks are often
perceived to be higher than leaving the customers vulnerable.  Surely
Microsoft's legal department has such concerns as well, but unlike
anyone else, the company takes these risks in the interest of
protecting its protecting its customers (from its own products 8-) --
but that's a different story).  Of course, Microsoft advisories tend
to contain more factual errors than the competition (sometimes even
very embarrassing ones, but that's life), but given the rate at which
these advisories are improving, we are steadily approaching the
optimum you can get if you rule out full disclosure. [1]

Furthermore, it's disheartening that the Linux project is neither able
to provide a security contact (some subsystem maintainers deal with
reports in a, ahem, rather strange way), nor able to issue _any_
advisories on their own.  The resulting Chinese Whispers syndrome
leads to a lot of misinformation, and might put Linux users
unnecessarily at risk.

1. This is about the detailed English advisories.  Translated versions
   seem to lack many of those qualities.

-- 
Florian Weimer 	                  [email protected]
University of Stuttgart           http://CERT.Uni-Stuttgart.DE/people/fw/
RUS-CERT                          fax +49-711-121-3688