Mick wrote:
On 17/06/06, Raymond Lewis Rebbeck <[EMAIL PROTECTED]> wrote:

I believe any potential security problems would only concern you if you were
running a telnet daemon not just using a client.

All telnet apps mentioned in the thread have glsa's about them re:
buffer overflows.

They do?

http://www.gentoo.org/security/en/glsa/

I can't find any *current* GLSAs regarding netcat and telnet.

telnet-bsd: http://security.gentoo.org/glsa/glsa-200504-01.xml 2005 - rather
old. Current Versions in portage are not affected.

netkit-telnet: http://security.gentoo.org/glsa/glsa-200503-36.xml 2005, again.
Fixed in currently available versions.
http://security.gentoo.org/glsa/glsa-200410-03.xml 2004. no comment.

And that's it.

So, I disagree and stand to what I just wrote. I know of no security
problems.

 On the other hand I won't be running them for any
great length of time, so it may be OK.

Actually, that's IMO a wrong attitude. Also a short exposure makes you
vulnerable. If the software would be vulnerable, also a short "attack"
might be sufficient to break into your system.

BUT: As there are no GLSAs, I'd say that there are no currently known
security problems.

Alexander Skwar
--
<Knghtbrd> glDisable (GL_BUGS);
<Endy> heh
<Endy> Is that in 1.2? :)
--
gentoo-user@gentoo.org mailing list

Reply via email to