[sldev] MAJOR/CRITICAL exploit for webbrowsers and SL?

Aidan Thornton makosoft at googlemail.com
Tue Sep 18 11:55:24 PDT 2007


On 9/18/07, Lawson English <lenglish5 at cox.net> wrote:
> Erik Anderson wrote:
> > You know, if this is an actual exploit then this list may not be the
> > appropriate place to continue discussions, I'm sorry that I
> > contributed at this point.
> >
>
> The whole point of open source , vis a vis exploints is to get these
> things out  in the open AND FIXED asap. Or such ha always been the claim
> of the open source community (or so I thought).
>
> Certainly, since it appeared on a public webpage, there's no hiding the
> vulnerability.
>

The person who discovered the exploit also posted it on the
full-disclosure mailing list 2 days or so ago, so I'd say the cat's
well and truly out the bag. (It's a very well-known and fairly widely
followed security mailing list, which means that lots of interesting
individuals now know about it.)


More information about the SLDev mailing list