Disclosure policy

Disclosure policy

This document outlines the policy used by SecurityLab to inform product vendors, customers and the general public about detected flaws and publicly disclose information about vulnerabilities.

SecurityLab takes responsibility to inform vendors about flaws discovered in their products and is ready to cooperate with vendors to eliminate vulnerabilities or deploy workarounds.

  1. If vendor does not provide security contacts, SecurityLab will send an email containing a request to certain public e-mail addresses associated with the vendor. According to the SecurityLab policy we never submit information about vulnerabilities via online forms, but we may use these forms to request contact information.
  2. When a security contact or other relevant e-mail address has been identified, information about discovered vulnerability is sent to vendor.
  3. In case the vendor does not respond to the initial email within five work days, the mail is resent. If the vendor does not respond to the second email within five work days, SecurityLab may publicly disclose vulnerability details.
  4. If the vendor replies:
    • An email with vulnerability details and preset disclosure date will be sent to the vendor. A new disclosure date may be set in case the vendor cannot meet the preset date.
    • SecurityLab expects constant status updates from the vendor. If status updates are not a part of the vendor’s policy, SecurityLab will send monthly status update requests.
    • If the vendor does not reply to status update request within 5 work days, it is resent.
    • If the vendor does not reply to the second status update request, SecurityLab may publicly disclose vulnerability details in 5 work days without further notice.
  5. Vulnerability details may be publicly disclosed when:
    • the preset/agreed disclosure date is reached
    • the vendor issues a fix or security advisory
    • the third party publicly discloses vulnerability details
    • active Exploitation of any form or a PoC code is observed on the Internet
    • the vendor does not issue a fix within 6 month from the initial contact date.
    • the vendor acts irresponsibly during the process of vulnerability notification, mitigation, and response coordination. The following are examples of what SecurityLab considers irresponsible acts:
      • Indirectly disclosing the vulnerability by releasing patches without an accompanying advisory notice.
      • Releasing a patch for one affected product version while leaving another affected version unpatched.
      • The vendor becomes unresponsive.
  6. SecurityLab reserves the right to pass information about discovered vulnerabilities to the Positive Technologies Research Team for future use in XSpider, MaxPatrol and other products.
  7. SecurityLab reserves the right to speed up disclosure of vulnerability details, having previously informed the vendor.
  8. Some vulnerability details (security advisory ID, vendor's name, exploitation vector, threat level and advisory issue date) are publicly disclosed before contacting the vendor (see #9).
  9. Vulnerability details are publicly disclosed on the following web sites:

Document version 1.1

Cisco Security Advisory: Multiple Vulnerabilities in Cisco IronPort Encryption Appliance

Cisco IronPort Encryption Appliance devices contain two vulnerabilities that allow remote, unauthent ...

11 february, 2010

Cisco Security Advisory: Multiple Cisco WebEx WRF Player Vulnerabilities

Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) Pla ...

18 december, 2009

Cisco Security Advisory: Transport Layer Security Renegotiation Vulnerability

An industry-wide vulnerability exists in the Transport Layer Security (TLS) protocol that co ...

23 november, 2009

MS10-017: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150)

This security update resolves seven privately reported vulnerabilities in Microsoft Office Excel.

09 march, 2010

MS10-016: Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (975561)

This security update addresses a privately reported vulnerability in Windows Movie Maker and Microso ...

09 march, 2010

MS10-015: Vulnerabilities in Windows Kernel Could Allow Elevation of Privilege (977165)

This security update resolves one publicly disclosed and one privately reported vulnerability in Mic ...

10 february, 2010

SunOS 5.10_x86: ucode driver patch

6905530 processor microcode code can panic when retrieving microcode revision.

02 february, 2010

Security Vulnerabilities in PostgreSQL Shipped With Solaris May Allow Escalation of Privileges or Man-in-the-Middle on SSL Connections

Multiple security vulnerabilities have been identified in the PostgreSQL software shipped with Solar ...

31 december, 2009

Directory Proxy Server Provided with Directory Server Enterprise Edition 6 is Subject to Denial of Service (DoS) and May Allow Unauthorized Access to Certain Data

Directory Proxy Server Provided with Directory Server Enterprise Edition 6 is Subject to Denial of S ...

31 december, 2009