Cisco declines disclosure grace period, bug gets released
code.google.com
code.google.com
So it sounds like they were aware of the issue, communicated out a fix would be in place but 7 days later than the expiration. Someone didn't want to budge those 7 days and released it anyway.
Not that its a big flaw but it seems a bit inflexible. Companies as large and as old as Cisco don't move very fast..
is it only Windows 8 that is affected? we don't have that deployed anywhere at my company. :)
"At the time this alert was first published, all versions of Cisco AnyConnect Secure Mobility Client for Windows were vulnerable." and no mention of Windows 8 specifically in Cisco's page suggests that this works on any version of Windows where the application runs.
A wise company would consider disclosing the bug even without a patch, using the rationale that their customers deserve to know that the bug exists and make decisions and implement workarounds to mitigate it.
In other words, public disclosure may be in the best interests of Cisco's customers.