Re: [SLUG] Ecartis mailing list manager, flawfinder and security

2002-12-02 Thread Malcolm V
On Sun, 2002-12-01 at 19:19, Erik de Castro Lopo wrote: Hi all, At Firday's nights meeting I said that I had been looking at the Ecartis Mailing List Manager http://www.ecartis.org/ and had found some potentially dangerous uses of the standard C sscanf() function using

Re: [SLUG] Ecartis mailing list manager, flawfinder and security

2002-12-02 Thread Rev Simon Rumble
On Sun 01 Dec, Erik de Castro Lopo bloviated thus: Anyway, Ecartis is now looking like a really nice Mailing List Manager although I still have to complete my code review of it. Yes I've been using it for a few years now. It used to be called listar but apparently there was some dispute over

[SLUG] Ecartis mailing list manager, flawfinder and security

2002-12-01 Thread Erik de Castro Lopo
Hi all, At Firday's nights meeting I said that I had been looking at the Ecartis Mailing List Manager http://www.ecartis.org/ and had found some potentially dangerous uses of the standard C sscanf() function using FlawFinder: http://www.dwheeler.com/flawfinder/ I have now reviewed