Re: Bug#278777: xsok: unfixed buffer overflow (CAN-2004-0074)

2004-11-01 Thread Martin Schulze
Steve Kemp wrote: > On Fri, Oct 29, 2004 at 10:12:33PM +0200, Frank Lichtenheld wrote: > > > Perhaps someone with a little more experience in identifying security > > problems should take a look, too. I CC'ed debian-security. > > Here's a quick summery : > > To be clear there are three flaws

Re: Bug#278777: xsok: unfixed buffer overflow (CAN-2004-0074)

2004-11-01 Thread Frank Lichtenheld
On Mon, Nov 01, 2004 at 11:02:21AM +, Steve Kemp wrote: > On Fri, Oct 29, 2004 at 10:12:33PM +0200, Frank Lichtenheld wrote: > > > Perhaps someone with a little more experience in identifying security > > problems should take a look, too. I CC'ed debian-security. > > Here's a quick summery

Re: Bug#278777: xsok: unfixed buffer overflow (CAN-2004-0074)

2004-11-01 Thread Steve Kemp
On Fri, Oct 29, 2004 at 10:12:33PM +0200, Frank Lichtenheld wrote: > Perhaps someone with a little more experience in identifying security > problems should take a look, too. I CC'ed debian-security. Here's a quick summery : To be clear there are three flaws being discussed in xsok: CAN-

Re: Bug#278777: xsok: unfixed buffer overflow (CAN-2004-0074)

2004-10-29 Thread Frank Lichtenheld
tags 278777 security thanks On Fri, Oct 29, 2004 at 09:46:00PM +0200, Thomas Wana wrote: > Frank Lichtenheld wrote: > > > >But you too, since that was the wrong part ;) The LANG vuln is fixed in > >the current package (the patch is in debian/patches and gets applied at > >build time). I guess the