Subject: Re: [PINE-CERT-20020301] OpenSSH off-by-one
To: None <tech-security@netbsd.org>
From: Joseph Frazee <frazee.23@osu.edu>
List: tech-security
Date: 03/07/2002 13:37:32
At 01:26 PM 3/7/2002, Steven M. Bellovin wrote:
>Absolutely.  There are several other recent bugtraq postings that also
>merit either advisories or pkgsrc security warnings, such as the buffer
>overflows in cfsd and apache, and the ipsec forwarding problem.

I haven't really followed bugtraq closely until the past 4 or 5 months and 
something about this doesn't sit with me well. This would make it nearly 7 
days between appearance on bugtraq and "full disclosure". What can be done 
to improve this?


Joe



Joseph Frazee
The OSU Libraries
UNIX Manager

e-mail: frazee.23@osu.edu
phone: (614) 688-5432
pager: (614) 201-2699