Re: brief report on NTLM buffer overflow

2005-10-17 Thread Mauro Tortonesi
Daniel Stenberg wrote: On Fri, 14 Oct 2005, Noèl Köthe wrote: The last paragraph says something like: Notable is the fast time of reaction of the Open Source developer: two days ago the problem was reported, yesterday corrected packages were produced and details of the vulnerability were

brief report on NTLM buffer overflow

2005-10-14 Thread Mauro Tortonesi
i am not going to publish a complete security advisory on this topic, but i think wget users deserve a little bit more information about the security vulnerability that was fixed yesterday, october 13th 2005. yesterday i was notified by iDEFENSE of a remotely exploitable buffer overflow in

Re: brief report on NTLM buffer overflow

2005-10-14 Thread Daniel Stenberg
On Fri, 14 Oct 2005, Noèl Köthe wrote: The last paragraph says something like: Notable is the fast time of reaction of the Open Source developer: two days ago the problem was reported, yesterday corrected packages were produced and details of the vulnerability were published. Just want to