Mick wrote:
On 17/06/06, Raymond Lewis Rebbeck <[EMAIL PROTECTED]> wrote:
I believe any potential security problems would only concern you if you were
running a telnet daemon not just using a client.
All telnet apps mentioned in the thread have glsa's about them re:
buffer overflows.
They do?
http://www.gentoo.org/security/en/glsa/
I can't find any *current* GLSAs regarding netcat and telnet.
telnet-bsd: http://security.gentoo.org/glsa/glsa-200504-01.xml 2005 - rather
old. Current Versions in portage are not affected.
netkit-telnet: http://security.gentoo.org/glsa/glsa-200503-36.xml 2005, again.
Fixed in currently available versions.
http://security.gentoo.org/glsa/glsa-200410-03.xml 2004. no comment.
And that's it.
So, I disagree and stand to what I just wrote. I know of no security
problems.
On the other hand I won't be running them for any
great length of time, so it may be OK.
Actually, that's IMO a wrong attitude. Also a short exposure makes you
vulnerable. If the software would be vulnerable, also a short "attack"
might be sufficient to break into your system.
BUT: As there are no GLSAs, I'd say that there are no currently known
security problems.
Alexander Skwar
--
<Knghtbrd> glDisable (GL_BUGS);
<Endy> heh
<Endy> Is that in 1.2? :)
--
gentoo-user@gentoo.org mailing list