Re: RedHat: Buffer Overflow in ls and mkdir

2004-10-28 Thread Jonas Anderson
On Sun, 24 Oct 2004, Thomas Sparrevohn wrote: On Sunday 24 October 2004 23:00, FreeBSD questions mailing list wrote: On 24 okt 2004, at 23:57, RedHat Security Team wrote: Dear RedHat user, huh? I thought I ran FreeBSD... I guess so did I - not really sure that there are any

Re: RedHat: Buffer Overflow in ls and mkdir

2004-10-25 Thread Dave Horsfall
On Sun, 24 Oct 2004, Matt Navarre wrote: Isn't linux_base based on RedHat? There are ls and mkdir binaries in /usr/compat/linux/bin, I suppose those could be affected by this. Over on Full-Disclosure they reckon it's a trojan, as it's unsigned and not in the usual format for such

Re: RedHat: Buffer Overflow in ls and mkdir

2004-10-25 Thread Matt Navarre
On Monday 25 October 2004 12:07, Dave Horsfall wrote: On Sun, 24 Oct 2004, Matt Navarre wrote: Isn't linux_base based on RedHat? There are ls and mkdir binaries in /usr/compat/linux/bin, I suppose those could be affected by this. Over on Full-Disclosure they reckon it's a trojan, as it's

Re: RedHat: Buffer Overflow in ls and mkdir

2004-10-25 Thread Don Tyson
On Monday 25 October 2004 12:07, Dave Horsfall wrote: On Sun, 24 Oct 2004, Matt Navarre wrote: Isn't linux_base based on RedHat? There are ls and mkdir binaries in /usr/compat/linux/bin, I suppose those could be affected by this. Over on Full-Disclosure they reckon it's a trojan, as

RedHat: Buffer Overflow in ls and mkdir

2004-10-24 Thread RedHat Security Team
[logo_rh_home.png] Original issue date: October 20, 2004 Last revised: October 20, 2004 Source: RedHat A complete revision history is at the end of this file. Dear RedHat user, Redhat found a vulnerability in fileutils (ls and mkdir), that could allow a remote attacker

Re: RedHat: Buffer Overflow in ls and mkdir

2004-10-24 Thread FreeBSD questions mailing list
On 24 okt 2004, at 23:57, RedHat Security Team wrote: [logo_rh_home.png] Original issue date: October 20, 2004 Last revised: October 20, 2004 Source: RedHat A complete revision history is at the end of this file. Dear RedHat user, huh? I thought I ran FreeBSD...

Re: RedHat: Buffer Overflow in ls and mkdir

2004-10-24 Thread Thomas Sparrevohn
On Sunday 24 October 2004 23:00, FreeBSD questions mailing list wrote: On 24 okt 2004, at 23:57, RedHat Security Team wrote: [logo_rh_home.png] Original issue date: October 20, 2004 Last revised: October 20, 2004 Source: RedHat A complete revision history is at the

Re: RedHat: Buffer Overflow in ls and mkdir

2004-10-24 Thread Matt Navarre
Thomas Sparrevohn wrote: On Sunday 24 October 2004 23:00, FreeBSD questions mailing list wrote: On 24 okt 2004, at 23:57, RedHat Security Team wrote: [logo_rh_home.png] Original issue date: October 20, 2004 Last revised: October 20, 2004 Source: RedHat A complete revision history is at

Re: RedHat: Buffer Overflow in ls and mkdir

2004-10-24 Thread Alec Berryman
begin quotation of FreeBSD questions mailing list on 2004-10-25 00:00:56 +0200: On 24 okt 2004, at 23:57, RedHat Security Team wrote: snip Dear RedHat user, huh? I thought I ran FreeBSD... This fake security notice references the GNU fileutils, which are now called coreutils and

Re: RedHat: Buffer Overflow in 'ls' and 'mkdir'

2004-10-24 Thread Hugo Silva
This is a fake! DONT download the patch (linux users), it is a trojaned version. Check: http://www.linux.ie/pipermail/ilug/2004-October/019483.html [logo_rh_home.png] Original issue date: October 20, 2004 Last revised: October 20, 2004 Source: RedHat A complete revision

Re: RedHat: Buffer Overflow in 'ls' and 'mkdir'

2004-10-24 Thread Rob
Hugo Silva wrote: This is a fake! DONT download the patch (linux users), it is a trojaned version. Check: http://www.linux.ie/pipermail/ilug/2004-October/019483.html A complete revision history is at the end of this file. Dear RedHat user, Above pipermail tracked down the source location. Is