<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: What If All Vulnerabilities Had This Disclosure Timeline?</title>
	<atom:link href="http://www.veracode.com/blog/2008/02/what-if-all-vulnerabilities-had-this-disclosure-timeline/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.veracode.com/blog/2008/02/what-if-all-vulnerabilities-had-this-disclosure-timeline/</link>
	<description>Application security testing, analysis, and metrics</description>
	<lastBuildDate>Fri, 10 Feb 2012 12:18:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Evgeny Legerov</title>
		<link>http://www.veracode.com/blog/2008/02/what-if-all-vulnerabilities-had-this-disclosure-timeline/comment-page-1/#comment-773</link>
		<dc:creator>Evgeny Legerov</dc:creator>
		<pubDate>Sun, 10 Feb 2008 21:41:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=78#comment-773</guid>
		<description>Nice to see updated post, thanks.
FYI - http://elegerov.blogspot.com/2008/02/i-will-be-adding-3-absolutely-new-bugs.html</description>
		<content:encoded><![CDATA[<p>Nice to see updated post, thanks.<br />
FYI &#8211; <a href="http://elegerov.blogspot.com/2008/02/i-will-be-adding-3-absolutely-new-bugs.html" rel="nofollow">http://elegerov.blogspot.com/2008/02/i-will-be-adding-3-absolutely-new-bugs.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: none</title>
		<link>http://www.veracode.com/blog/2008/02/what-if-all-vulnerabilities-had-this-disclosure-timeline/comment-page-1/#comment-772</link>
		<dc:creator>none</dc:creator>
		<pubDate>Sat, 09 Feb 2008 13:34:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=78#comment-772</guid>
		<description>CG:  Your missing the point. The statement that gleg made ...

&quot;Gleg founder Evgeny Legerov confirmed his company’s refusal to share the RealPlayer exploit details, arguing that he needs “exclusivity” for a few months to help his customers understand the level of risk they face.&quot;

... is completely absurd. With each day that gleg doesn&#039;t tell Real he puts his clients at a greater risk. His client should demand that he inform Real so that a patch can be made available to them.</description>
		<content:encoded><![CDATA[<p>CG:  Your missing the point. The statement that gleg made &#8230;</p>
<p>&#8220;Gleg founder Evgeny Legerov confirmed his company’s refusal to share the RealPlayer exploit details, arguing that he needs “exclusivity” for a few months to help his customers understand the level of risk they face.&#8221;</p>
<p>&#8230; is completely absurd. With each day that gleg doesn&#8217;t tell Real he puts his clients at a greater risk. His client should demand that he inform Real so that a patch can be made available to them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Evgeny Legerov</title>
		<link>http://www.veracode.com/blog/2008/02/what-if-all-vulnerabilities-had-this-disclosure-timeline/comment-page-1/#comment-771</link>
		<dc:creator>Evgeny Legerov</dc:creator>
		<pubDate>Sat, 09 Feb 2008 12:17:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=78#comment-771</guid>
		<description>my comments here - http://elegerov.blogspot.com/</description>
		<content:encoded><![CDATA[<p>my comments here &#8211; <a href="http://elegerov.blogspot.com/" rel="nofollow">http://elegerov.blogspot.com/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: asdf</title>
		<link>http://www.veracode.com/blog/2008/02/what-if-all-vulnerabilities-had-this-disclosure-timeline/comment-page-1/#comment-770</link>
		<dc:creator>asdf</dc:creator>
		<pubDate>Sat, 09 Feb 2008 09:35:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=78#comment-770</guid>
		<description>this link http://isc.sans.org/diary.html?storyid=3810 actually mentioned old RealPlayer 11 activex exploit http://www.kb.cert.org/vuls/id/871673</description>
		<content:encoded><![CDATA[<p>this link <a href="http://isc.sans.org/diary.html?storyid=3810" rel="nofollow">http://isc.sans.org/diary.html?storyid=3810</a> actually mentioned old RealPlayer 11 activex exploit <a href="http://www.kb.cert.org/vuls/id/871673" rel="nofollow">http://www.kb.cert.org/vuls/id/871673</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CG</title>
		<link>http://www.veracode.com/blog/2008/02/what-if-all-vulnerabilities-had-this-disclosure-timeline/comment-page-1/#comment-762</link>
		<dc:creator>CG</dc:creator>
		<pubDate>Thu, 07 Feb 2008 06:41:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=78#comment-762</guid>
		<description>and how in all that is gleg supposed to pay the rent? 

it seems the days of vendors getting vulnerability information for free are over, besides a subscription to canvas isnt even close what you would pay someone with the skill to go thru and find and fix that code anyway.</description>
		<content:encoded><![CDATA[<p>and how in all that is gleg supposed to pay the rent? </p>
<p>it seems the days of vendors getting vulnerability information for free are over, besides a subscription to canvas isnt even close what you would pay someone with the skill to go thru and find and fix that code anyway.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Spire Security Viewpoint</title>
		<link>http://www.veracode.com/blog/2008/02/what-if-all-vulnerabilities-had-this-disclosure-timeline/comment-page-1/#comment-761</link>
		<dc:creator>Spire Security Viewpoint</dc:creator>
		<pubDate>Thu, 07 Feb 2008 04:28:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.veracode.com/blog/?p=78#comment-761</guid>
		<description>&lt;strong&gt;The Hot Potato of Blame in the Vulnerability Game...&lt;/strong&gt;

... (or should I say Potatoe in honor of primary season? ;-)) Chris over at Zero in a Bit has a thoughtful post on the timeline for the recent Real Player vulnerability found by Gleg. This strikes me as the type of thing we need to learn to live with. ...</description>
		<content:encoded><![CDATA[<p><strong>The Hot Potato of Blame in the Vulnerability Game&#8230;</strong></p>
<p>&#8230; (or should I say Potatoe in honor of primary season? ;-)) Chris over at Zero in a Bit has a thoughtful post on the timeline for the recent Real Player vulnerability found by Gleg. This strikes me as the type of thing we need to learn to live with. &#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

