Why even BOTHER reporting bugs to vendors?
Here it is – the argument for why the VulnDisco path is better than the CERT path or, that is to say, why it’s better to sell people tools that can be used to verify the fix (vendor or DIY) vs. only telling the vendor then relying on the vendor’s quality, honesty and other things vendors typically don’t seem to have.
I say that folks like Adobe should have even MORE interest in things like Immunity Early Access PLUS. I mean really, why should I have to play middle-man between the researcher who wrote the plug-in and the vendor with the bug? Because Adobe and others think they’re above paying a third party for insight into their own product’s quality.
This vulnerability is originates from CVE-2006-3459 was reported by Tavis Ormandy, Google Security Team. Adobe just fixed AcroForm.api file ,but ImageConversion.api still have a vulnerability too.
via Security-Sucks » CVE-2010-0188, APSB10-07 PDF Exploit demonstration.
Posted: February 24th, 2010
at 9:16pm by tan
Tagged with AcroForm.api, Adobe, Canvas, CERT, CVE-2006-3459, Google Security Team, ImageConversion.api, Tavis Ormandy, vulndisco
Categories: Breaking News
Comments: No comments









