|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
The non-apreciated world of full-disclosure
From: Davide Del Vecchio (dante
alighieri.org)
Date: Wed Mar 03 2004 - 02:33:04 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
16 days after my post regarding the Firewall/VPN Appliance vuln
and 1 month more my TELEPHONE notice to Symantec support,
Symantec released a new version of firmware for their appliance.
But the problem it`s not the time.
The problem is that they told me it was "not a vulnerability",
after 1 month they released the new firmare to patch the "Cached Password
Vulnerability" (as they called it), and just telling
"Symantec is aware of a potential administrator password leakage
vulnerability reported in
<http://securitytracker.com/alerts/2004/Feb/1009069.html>."
...
This is what I received..I don`t want money
but I think an ufficial "thank you" is the minimum... or not?
Am I telling something of MAD?!
the new firmware is avaiable here:
ftp://ftp.symantec.com/public/english_us_canada/products/symantec_firewall_v
pn_appliance/updates/vpn200_161_app.zip
d.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Davide Del Vecchio "Dante Alighieri" dante
alighieri.org ~ dante
bluejack.it
http://www.alighieri.org http://www.bluejack.it http://www.ezln.it
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]