[VulnDiscuss] CAN-2003-0552 (and advisory quality)
Florian Weimer <[email protected]> Mon, 28 Jul 2003 22:44:51 +0200
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Message-ID | <[email protected]> |
You might have noticed the following paragraph in the Red Hat advisory: | CAN-2003-0552: Jerry Kreuscher discovered that the Forwarding table | could be spoofed by sending forged packets with bogus source | addresses the same as the local host. This looks pretty scary at first sight, but is apparently relevant to bridges (not routers), see Herbert Xu's message in: <http://lists.debian.org/debian-security/2003/debian-security-200307/msg00140.html> So it's not a big problem. But better check it yourself, you know the drill: get the SRPM, pipe it through rpm2cpio, and look at the diffs with the most recent date -- as usual. Anyway, this is a fine example that currently, large parts of the Free Software community cannot resolve security issues in a reasonable manner. Just compare Red Hat's patch availability notice (it's nothing more than that) to one of the more recent Microsoft advisories. You know something is wrong if Microsoft, the leader in the movement to end information security "anarchy", is offering much more detailed information than the competition. Apparently, few companies are willing to face the legal risk of spreading misinformation in advisories, as such risks are often perceived to be higher than leaving the customers vulnerable. Surely Microsoft's legal department has such concerns as well, but unlike anyone else, the company takes these risks in the interest of protecting its protecting its customers (from its own products 8-) -- but that's a different story). Of course, Microsoft advisories tend to contain more factual errors than the competition (sometimes even very embarrassing ones, but that's life), but given the rate at which these advisories are improving, we are steadily approaching the optimum you can get if you rule out full disclosure. [1] Furthermore, it's disheartening that the Linux project is neither able to provide a security contact (some subsystem maintainers deal with reports in a, ahem, rather strange way), nor able to issue _any_ advisories on their own. The resulting Chinese Whispers syndrome leads to a lot of misinformation, and might put Linux users unnecessarily at risk. 1. This is about the detailed English advisories. Translated versions seem to lack many of those qualities. -- Florian Weimer [email protected] University of Stuttgart http://CERT.Uni-Stuttgart.DE/people/fw/ RUS-CERT fax +49-711-121-3688