OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 2nd quarter (Apr-Jun) 1998: Re: CERT Vendor-Initiated Bulletin VB-98.04 - xterm.Xaw

Re: CERT Vendor-Initiated Bulletin VB-98.04 - xterm.Xaw

Perry E. Metzger (perrypiermont.com)
Thu, 30 Apr 1998 18:16:15 -0400

Theo de Raadt writes:
> What is this.  Is The Open Group now selling security patches only to
> their members?
>
> I asked the XFree86 people.  They have received no communication from TOG
> about this at all.  I think this is extremely bad ethics on the part of
> TOG to publish information on a security problem and then only give fixes
> to people who have given them money.

For once, I agree completely with Theo. It was bad enough that TOG
decided to turn X into proprietary software -- saying that security
patches for back revs are proprietary is nearly unacceptable behavior.

Perry