Re: [vendor-sec] Re: [Fwd: Vulnerabilities in Lilo 22.6.1 and previous versions]

2008-08-05 Thread Vesa Jääskeläinen
Vincent Danen wrote: * [2008-07-29 10:01:45 -0700] Mike Hamburg wrote: On Jul 29, 2008, at 5:45 AM, Jonathan Brossard wrote: 1) Plain text password disclosure. Required privileges to perform this operation are OS dependant, from unprivileged users under Windows (any), to root under most Unix.

Re: [vendor-sec] Re: [Fwd: Vulnerabilities in Lilo 22.6.1 and previous versions]

2008-07-29 Thread Vincent Danen
* [2008-07-29 18:15:36 +0530] Jonathan Brossard wrote: Dear Pierre Yves, (Cher Pierre Yves, meme ;), Thanks for the information, I'm forwarding your e-mail to the vendor-sec mailing list (in CC) since other linux distros could be interested, Thanks for relying the information, I really

Re: [vendor-sec] Re: [Fwd: Vulnerabilities in Lilo 22.6.1 and previous versions]

2008-07-29 Thread Mike Hamburg
On Jul 29, 2008, at 5:45 AM, Jonathan Brossard wrote: 1) Plain text password disclosure. Required privileges to perform this operation are OS dependant, from unprivileged users under Windows (any), to root under most Unix. 2) A privileged attacker able to write to the MBR and knowing the

Re: [vendor-sec] Re: [Fwd: Vulnerabilities in Lilo 22.6.1 and previous versions]

2008-07-29 Thread Vincent Danen
* [2008-07-29 10:01:45 -0700] Mike Hamburg wrote: On Jul 29, 2008, at 5:45 AM, Jonathan Brossard wrote: 1) Plain text password disclosure. Required privileges to perform this operation are OS dependant, from unprivileged users under Windows (any), to root under most Unix. 2) A privileged