Hi Ken, Looks like there's another one:
Symantec Y2K10 Date Stamp Bug Hits Endpoint Protection Manager http://www.eweek.com/c/a/Security/Symantec-Y2K10-Date-Stamp-Bug-Hits-Endpoint-Protection-Manager-472518/?kc=EWKNLSTE01072010STR1 I am VERY curious to learn how these happened... Only using the last digit of the year? Hard for me to believe. Maybe it's in a single API and somebody tried to be too clever with some bit-shifting. Stephen -- http://www.linkedin.com/in/stephencraigevans On Thu, Jan 7, 2010 at 8:45 AM, Kenneth Van Wyk <k...@krvw.com> wrote: > FYI, below is a link to an article with some additional impact details of the > "2010 bug" that's been cropping up in various places. Still no light being > shed on the actual programming error, though. I think it would make a > fascinating case study, or at least discussion, here. > > http://www.guardian.co.uk/world/2010/jan/06/2010-bug-millions-germans > > > Cheers, > > Ken > > ----- > Kenneth R. van Wyk > KRvW Associates, LLC > http://www.KRvW.com > > (This email is digitally signed with a free x.509 certificate from CAcert. If > you're unable to verify the signature, try getting their root CA certificate > at http://www.cacert.org -- for free.) > > > > > > > _______________________________________________ > Secure Coding mailing list (SC-L) SC-L@securecoding.org > List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l > List charter available at - http://www.securecoding.org/list/charter.php > SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) > as a free, non-commercial service to the software security community. > _______________________________________________ > > _______________________________________________ Secure Coding mailing list (SC-L) SC-L@securecoding.org List information, subscriptions, etc - http://krvw.com/mailman/listinfo/sc-l List charter available at - http://www.securecoding.org/list/charter.php SC-L is hosted and moderated by KRvW Associates, LLC (http://www.KRvW.com) as a free, non-commercial service to the software security community. _______________________________________________