_
28-Aug-2008 | 22:48:51

News:

.



Bookmark Page
Bookmark on digg Bookmark on deli.cio.us Bookmark on reddit Bookmark on Technorati Bookmark on stumbleupon Bookmark on Google Bookmark on Yahoo MyWeb

Vulnerability Public Disclosure

Public Disclosure

The time of disclosure of a vulnerability is defined differently in the security community and industry. It is most commonly referred to as a kind of public disclosure of security information by a certain party. Usually, vulnerability information is discussed on a mailing list or published on a security web site and results in a security advisory afterwards. To ensure the quality and availability of relevant security information, we propose a more strict definition of the disclosure time.

Definition: Disclosure Date

The time of disclosure is the first date a security vulnerability is described on a channel where the disclosed information on the vulnerability has to fulfil the following requirements:
  1. the information is freely available to the public
  2. the vulnerability information is published by a trusted and independent channel/source
  3. the vulnerability has undergone analysis by experts such that risk rating information is included upon disclosure

Requirement 1

Requirement 2

Requirement 3