[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: where to start?




> 4) other, non-security bugs in the code .. no doubt we'll
>    encounter these when we take a closer look at the code
>    (also, these could be outside of the scope of this
>    project ???)

I say these are in the scope of the project.

In OpenBSD they fix any bug they find and happen to fix
security bugs by chance.  An example I have heard Theo speak
about was an obscure combination of 5 minor bugs in lpd where
by the time they were announced OpenBSD had squished some of
them because they were bugs without noticing security implications.


Kernel-audit:  discussion list for security and the linux kernel
Archive:       http://mail.nl.linux.org/kernel-audit/