Question regarding security information sharing between projects?
-
Do Alterware and Plutonium share information with each other regarding patched vulnerabilities before releasing patches or making public disclosures?
Let's say Alterware patched a vulnerability that was also usable against Plutonium (or vice versa), what would stop an attacker from reverse engineering the exploit from the patch, and targeting Plutonium users?
-
Yes.
But since many people refuse to update their iw4x there is, in theory still a good chance for things to be exploited.