[VulnDiscuss] CERT
"Mark Litchfield" <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq |
|---|---|
| Message-ID | <002701c2c710$5a713d10$0100a8c0@liberty> |
Copy of mail sent to CERT: Dear CERT, It has come to my attention, that the 6 vulnerabilities that I recently submitted to the vendor and yourselves has been leaked to certain organisations and government departments. I know this as the vendor has asked whether I knew the following, and has also voiced to me their views on your actions: Vendor Quote: "By the way, were you aware of CERT's policy of advance disclosure to certain parties?" In submitting vulnerabilities to yourselves, I do so as an act of good faith to encourage the communication of the vulnerability to the IT administrators that it will affect with a view to increasing the patch uptake. I do not expect the issue to be disclosed to any parties; I believe that this choice remains with the discoverer or discovering company and the vendor of the software. I consider these actions made by yourselves as unprofessional, and as far as I am concerned I feel a betrayal in the trust that was extended to your organisation by myself. It is with great regret, that based on your actions, NGS software who published 47 vulnerabilities in 2002, will no longer support CERT in any fashion. Despite being a competitor, I think it only fair to mention that ISS's reasons for not wishing to inform CERT on the Apache Transfer Encoding Chunked Issue have now been clearly justified. I am posting this to the mailing lists so that independent or corporate researchers are aware of your practice. I just hope that the other organisations offering a similar service as a Vulnerability pre-disclosure clearing house are not following the same path. Regrettably Mark Litchfield NGS Software Ltd http://www.ngssoftware.com/ Tel: +44 208 40 100 70 (London) Tel: +44 1241 431 267 Mobile: +44 790 069 5236 Email: [email protected]