Re: [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-08:02.libc

2008-01-15 Thread Pietro Cerutti
Pietro Cerutti wrote: # fetch http://security.FreeBSD.org/patches/SA-08:02/libc.patch The off-by-one error is still there.. Errata corrige: the off-by-one error is in my head... -- Pietro Cerutti PGP Public Key: http://gahr.ch/pgp signature.asc Description: OpenPGP digital signature

FreeBSD Security Advisory FreeBSD-SA-08:02.libc

2008-01-14 Thread FreeBSD Security Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 = FreeBSD-SA-08:02.libc Security Advisory The FreeBSD Project Topic:

Re: FreeBSD Security Advisory FreeBSD-SA-08:02.libc

2008-01-14 Thread Mike Tancsa
At 06:09 PM 1/14/2008, FreeBSD Security Advisories wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 = FreeBSD-SA-08:02.libc Security Advisory

Re: FreeBSD Security Advisory FreeBSD-SA-08:02.libc

2008-01-14 Thread Mike Tancsa
At 12:22 AM 1/15/2008, Mark Andrews wrote: For the usual suspects of applications running, (e.g. sendmail, apache, BIND etc) would it be possible to pass crafted packets through to this function remotely via those apps ? ie how easy is this to do ? The usual suspects don't call

Re: FreeBSD Security Advisory FreeBSD-SA-08:02.libc

2008-01-14 Thread Mark Andrews
At 06:09 PM 1/14/2008, FreeBSD Security Advisories wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 = FreeBSD-SA-08:02.libc Security Advisor y

Re: FreeBSD Security Advisory FreeBSD-SA-08:02.libc

2008-01-14 Thread Garrett Wollman
On Mon, 14 Jan 2008 23:28:46 -0500, Mike Tancsa [EMAIL PROTECTED] said: For the usual suspects of applications running, (e.g. sendmail, apache, BIND etc) would it be possible to pass crafted packets through to this function remotely via those apps ? ie how easy is this to do ?

Re: FreeBSD Security Advisory FreeBSD-SA-08:02.libc

2008-01-14 Thread Gregory Shapiro
Topic: inet_network() buffer overflow For the usual suspects of applications running, (e.g. sendmail, apache, BIND etc) would it be possible to pass crafted packets through to this function remotely via those apps ? ie how easy is this to do ? Speaking solely for sendmail, this