Bugtraq mailing list archives

Re: HP security bug report contact?


From: steve () gbnet org (Steve Kennedy)
Date: Sun, 4 Sep 1994 10:55:16 +0100 (BST)


According to Helen O'Boyle

Hi,
Just as the subject line says, to whom at HP do I report a security hold
in an hpux component?
Since this is HP-specific, I'll give HP a shot at it before I call CERT.

Report it to your local HP responce centre and tell them to escalate it !!!

Get names ...

Also report it to CERT who will also try and track it.

I had a big problem with HP reporting the old exec suid shell scripts
problem. Went to response centre and my contact bounced it as high as they
could. HP's view was that it was fixed in the next version of the OS so 'go
away'. I also reported it to CERT and it was never really resolved :-(

This affect HP700's and HP800's running HP-UX v8.0x - not present in
v7 or v9 ...

Regards

Steve

p.s. make SURE you get names all the way ...

-- 
 ___  |_  ___        ___           Flat 2, 43 Howitt Road
(___  |  (___) \  / (___)                    Belsize Park
 ___) |  (___   \/  (___                   London NW3 4LU
[MIME OK]                          tel +44-(0)71 483 1169
steve@gbnet.{com,org,net} home (or steve () tel net)
steve () marvin demon co uk  Demon Internet Dial-up
http://www.demon.co.uk/subscribers/m/marvin



Current thread: