• [^] # Re: Annonce bugtraq

    Posté par . En réponse à la dépêche HP utilise la menace du DMCA pour empêcher la publication d'une vulnérabilité. Évalué à 10.

    Le mec qui a posté l'exploit n'a pas été très correct, mais le problème c'est que HP était déjà au courant depuis longtemps (plusieurs mois voire un an), je cite le premier article de CNet:

    SnoSoft began talking with HP this spring about the group's research into Tru64 Unix's security flaws and had not intended to release the code publicly.
    [...]
    It is common to release "live" code that takes advantage of a security hole after notifying the company. In HP's case, SnoSoft says that information made public last year should have given the computer maker enough time to fix the problem.
    [...]
    HP has known about the Tru64 vulnerability "for some time," SnoSoft's Finisterre said, but never fixed the problem. An HP spokesman said he did not know if a patch had been released.

    Donc c'est un peu toujours pareil : on passe par la procèdure classique d'avertissement de l'éditeur avant de rendre le problème publique, mais s'il veut pas en tenir compte, ben c'est bien fait quand on lui met le nez dedans.