Disclosure policy

Disclosure policy

This document outlines the policy used by SecurityLab to inform product vendors, customers, and the general public about detected flaws and publicly disclose information about vulnerabilities.

SecurityLab takes responsibility to inform vendors about flaws discovered in their products and is ready to cooperate with vendors to eliminate vulnerabilities or develop workarounds.

If a vendor does not provide security contacts, SecurityLab will send an email containing a request to the vendor’s certain public e-mail addresses. According to the SecurityLab policy, submitting information about vulnerabilities via online forms is prohibited, although these forms may be used for requesting contact information. Once a security contact has been identified, an email is sent containing a notification about security issue and a request for a S/MIME certificate in order to send the detailed information in an encrypted form. If the certificate is not provided, vulnerability details will be sent unencrypted at the vendor's own risk. Otherwise, an encrypted email message containing all relevant information will be sent. Whether or not SecurityLab received a response from the vendor, vulnerability details will be sent to the Computer Emergency Response Team (CERT) in no longer than 20 days since the initial vendor contact. Upon receiving vulnerability details, CERT will publish a security advisory according to its own disclosure policy in the timeframe of about 45 days.

  • Vulnerability details are publicly disclosed on the following web sites:
  • Document version 1.2

    Cisco Security Advisory: Cisco Security Agent Remote Code Execution Vulnerabilities

    Cisco Security Agent is affected by vulnerabilities that could allow an unauthenticated attacker to ...

    27 october, 2011

    Cisco Security Advisory: Denial of Service Vulnerability in Cisco Video Surveillance IP Cameras

    A denial of service (DoS) vulnerability exists in the Cisco Video Surveillance IP Cameras 24 ...

    27 october, 2011

    Cisco Security Advisory: Cisco Unified Contact Center Express Directory Traversal Vulnerability

    Cisco Unified Contact Center Express (UCCX or Unified CCX) and Cisco Unified IP Interactive ...

    27 october, 2011

    MS12-007: Vulnerability in AntiXSS Library Could Allow Information Disclosure (2607664)

    This security update resolves one privately reported vulnerability in the Microsoft Anti-Cross Site ...

    10 january, 2012

    MS12-006: Vulnerability in SSL/TLS Could Allow Information Disclosure (2643584)

    This security update resolves a publicly disclosed vulnerability in SSL 3.0 and TLS 1.0.

    10 january, 2012

    MS12-005: Vulnerability in Microsoft Windows Could Allow Remote Code Execution (2584146)

    This security update resolves a privately reported vulnerability in Microsoft Windows.

    10 january, 2012

    This Alert covers CVE-2010-0896 for the mail component of the Sun Convergence product

    This Sun Alert covers CVE-2010-0896 for the mail component of the Sun Convergence product.

    14 april, 2010

    This Alert Covers CVE-2010-0893 for the Mail Component of the Sun Convergence Product

    This Alert covers CVE-2010-0893 for the mail component of the Sun Convergence product.

    14 april, 2010

    SunOS 5.10_x86: ucode driver patch

    6905530 processor microcode code can panic when retrieving microcode revision.

    02 february, 2010