Nov 30 2006
Oracle Bug-a-day cancelled due to …?
We can only assume that a plan to release a weeks worth of Oracle Database vulnerabilities was cancelled due to lawyers and threats to sue the pants off of Cesar Cerrudo if he went forward with the project. From what we’ve seen with Oracle in the past, I think this is probably a fairly safe assumption to make though. I wonder if Cesar had just named the project more generically, say ‘Week of Database Bugs’ instead, and then just published Oracle bugs if he couldn’t at least have gotten a few of the bugs out before the lawsuit threats began.
This is a graphic example of why I don’t believe vendors should be in charge of the disclosure process: it’s only in their best interest to cover up the vulnerbilities.
Technorati Tags: security, McKeay, Oracle, Vulnerability