<<< Date Index >>>     <<< Thread Index >>>

RE: defining 0day



> What do you, as professional, believe 0day should mean, 
> regardless of previous definitions?

  I think there is some slight residual usefulness to designating
vulnerabilities whose first public disclosure results from
discovery/analysis of an active exploit already "in the wild".  ("0 days"
thus being the elapsed time from public disclosure of the vulnerability to
appearance of a live threat exploiting it, a characteristic which an unknown
vulnerability may only aspire to, and a patched one may never live down.)

David Gillett