[VulnDiscuss] Re: SRT2003-11-02-0218 - NIPrint LPD-LPR Local Help API SYSTEM exploit

KF <[email protected]> Wed, 05 Nov 2003 15:04:25 -0500
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
Richard van den Berg wrote:

>>We are currently evaluating .pdf based advisory release... please let us
>>know if you have any issues with the pdf listed below.
>>    
>>
>
>Issue 1: it is in PDF which means I cannot read it unless I am running a
>graphical user interface
>
I certainly understand... this seems to be the general response from 
alot of folks... I am fairly sure we will offer both .pdf and .txt 
options in the future. The .pdf stuff will NOT be mandatory based on the 
public reaction.

>
>Issue 2: I have to register before I can access it
>
>I understand it is up to you how you want to offer this free information
>to the public. It surprises me that Vulnwatch allowed this message to
>pass, since there is no actual vulnerability information in the E-mail.
>
That is not entirely true... there was information relating to the 
nature of the vulnerabilities in both mails that went out. It may not 
have been the in depth technical information you crave however there is 
enough information for someone that runs NIPrint to let them know it has 
a security issue. As for the technical details... you guessed it... they 
are hiding behind the registration page.

>Personally I do not feel like registering on yet another site to get this
>information.
>
Of course there is always security-focus, sintelli and several other 
places to get the info for those of you that can wait until someone else 
picks up the details.

>
>Sincerely,
>
>Richard van den Berg
>
Thanks for the feedback

-KF


>
>  
>