Friday, July 17, 2009

SDK and 1.1

So, if the new version of the SDK is any inclination of how palm is doing with patching my reported security issues, then we are in good shape. From preliminary testing, the original bug from 1.0.3 seems good and the two (no credit on these i guess) that I had reported in 1.0.4 also seem to be fixed. Now if I can only get Palm to be ok with letting me talk to the details of them while coordinating my disclosure of at the time of the patch release.

With all that said, nothing from my latest advisory seems fixed, though there are some minor enhancements to make spotting the issues a little easier.

-Ladd

No comments:

Post a Comment