Re: [Full-disclosure] [ GLSA 200612-15 ] McAfee VirusScan: Insecure DT_RPATH

2006-12-14 Thread David_Coffey
Gentoo Security Team, On your security web page (http://www.gentoo.org/security/en/index.xml), you make the following statement about how you work with vendors in a professional manner: We work directly with vendors, end users and other OSS projects to ensure all security incidents are

Re: [Full-disclosure] [ GLSA 200612-15 ] McAfee VirusScan: Insecure DT_RPATH

2006-12-14 Thread Tavis Ormandy
On Thu, Dec 14, 2006 at 06:39:55PM -0600, [EMAIL PROTECTED] wrote: Gentoo Security Team, This statement seems to contrast greatly your practice of not following a professional responsible disclosure process; particularly, posting a security issue only 8.5 hours after your initial report was

[Full-disclosure] [ GLSA 200612-15 ] McAfee VirusScan: Insecure DT_RPATH

2006-12-13 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -