Adobe admits Tavis Ormandy responsible for Flash Player bug patches
Adobe last week acknowledged that as many as 80 bugs in Flash Player were reported by a Google security engineer, as it continued to defend its decision not to spell out details of the vulnerabilities.
Google also cited the same number, apparently putting to rest the spat between the engineer, Tavis Ormandy, and Adobe. In a pair of blog posts, Adobe and Google spelled out how the number "400" that Ormandy had cited ended up being cut by 80%.
"The initial run of the ongoing effort resulted in about 400 unique crash signatures, which were logged as 106 individual security bugs following the initial triage," said Brad Arkin, Adobe's senior director of product security and privacy. "As these bugs were resolved, many were identified as duplicates that weren't caught during the initial triage. In the final analysis, the Flash Player update we shipped earlier this week contains about 80 code changes to fix these bugs."