ProtonVPN and NordVPN reinforce incomplete patch for code execution bug

Discussion in 'privacy technology' started by guest, Sep 7, 2018.

  1. guest

    guest Guest

    ProtonVPN and NordVPN reinforce incomplete patch for code execution bug
    September 7, 2018
    https://www.scmagazine.com/home/new...orce-incomplete-patch-for-code-execution-bug/
     
  2. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    9,252
    Very interesting. I somehow doubt that this is coincidence. Maybe just shared resources, as discussed elsewhere. Or o_O
     
  3. 142395

    142395 Guest

    VerSprite's Github page mentioned in Talos' site describes many vulns in various VPN apps both on Windows & Mac, as well as the vendor's response time line.
    It can be very valuable source to evaluate these vendor's seriousness about security, as long as you take each vuln's detail (e.g. is it acceptable or silly?) into account.
     
  4. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    9,252
  5. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    vpn 101: stick with the stock ovpn sw.
     
  6. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
  7. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    9,252
  8. 142395

    142395 Guest

    Having vulns is not necessarily bad. But if you looked the page closer, you'll find some vendors repeatedly failed to fix the vuln or don't accept it as vuln.
    I think PIA's attitude is in a better side.
     
  9. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    9,252
    OK, maybe I'll do a full summary, including those cryptic *.md advisories.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.