But why should insecure argument handling bugs (as per your recent SSH bulletin) be found after release ?
Those are an ancient class of bugs that should be picked up by any competent security review.
Is your theory that "any competent security review" will find every security hole in a product? Because that sure would be great if it were true. Unfortunately it does not match my experience.
Is your theory that "any competent security review" will find every security hole in a product? Because that sure would be great if it were true. Unfortunately it does not match my experience.