Progress Software/Telerik Cease and Desist

sender
Progress Software
[Private] Bedford, MA, 01730, US Sent on COUNTRY: US 🇺🇸
recipient
PatchAdvisor, Inc.
[Private] Alexandria, VA, 22312, US

Re: Progress Software/Telerik Cease and Desist

Sent via: Email

Notice Type:
Other
Action taken:
Yes
Explanation of complaint

With regards to a blog post related to the vulnerability CVE-2[REDACTED] that contained:
- a guide for discovering and understanding the vulnerability
- limited output from a decompiler against the vulnerable product, when the output was related to understanding the vulnerability
- guidance on exploiting the vulnerability

Progress' council asserted that the blog post contained both an admission of reverse engineering the vulnerable product, and the product's source code.

Progress' council then asserted that the content of the blog post and actions described therein constituted a violation of their EULA, copyright infringement, misappropriation of trade secrets, a violation of the Computer Fraud and Abuse Act, a violation of the Defend Trade Secrets Act, and possibly other state and federal statutes.

Progress' council demanded the removal of the blog post, and to cease and desist publication or disclosure of Progress' source code in the future.

Tags
code decompilation progress telerik vulnerability cve-2017-9248
Jurisdictions
us