[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] Very minor heap address disclosure; measuring time to fix for [Firefox] [Internet Explorer] [Safari]
- To: full-disclosure <full-disclosure@xxxxxxxxxxxxxxxxx>
- Subject: [Full-disclosure] Very minor heap address disclosure; measuring time to fix for [Firefox] [Internet Explorer] [Safari]
- From: Chris Evans <scarybeasts@xxxxxxxxx>
- Date: Wed, 9 Mar 2011 20:09:20 -0800
Hi,
It's unusual to get both conditions:
- The exact same bug across multiple different codebases.
- Already partially disclosed.
So the rare opportunity will be seized to provide a direct comparison of
response quality and response time. Some might argue that this is a much
better metric than other common metrics such as "bug counting".
It's not serious by any stretch of the imagination, so those looking for
pwnage can stop reading.
Full details,
http://scarybeastsecurity.blogspot.com/2011/03/multi-browser-heap-address-leak-in-xslt.html
Who will handle it best? Results via @scarybeasts
Cheers
Chris
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/