[VIM] Question regarding ZDI-12-017's CVE

security curmudgeon jericho at attrition.org
Mon Jun 11 18:34:34 CDT 2012

: Thank you for the insight. I did not know this.
: I had just pinged Oracle for CVE's related to tomorrow's patches they 
: are releasing. I will go ahead and ask for this one as well.  Any others 
: that ZDI was a part of that you'd like Oracle CVE's for?

I don't think so at this time, but this comes up every patch cycle (just 
not specific to ZDI). We appreciate you and other researchers asking for 
the association. To this date, we still have 3rd party advisories on 
Oracle that we cannot associate with a CVE, some going back as far as 2007 
if memory serves.

