Mailing List ArchiveSupport open source code!
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] OpenBSD local exploit
- To: tlug@example.com
- Subject: Re: [tlug] OpenBSD local exploit
- From: Matt Doughty <mdoughty@example.com>
- Date: Fri, 12 Apr 2002 10:22:18 +0900
- Content-disposition: inline
- Content-transfer-encoding: 7bit
- Content-type: text/plain; charset=us-ascii
- In-reply-to: <20020412011528.GA6042@example.com>; from wileyc@example.com on Fri, Apr 12, 2002 at 10:15:28AM +0900
- Mail-followup-to: Matt Doughty <mdoughty@example.com>, tlug@example.com
- References: <200204110847.g3B8lb714329@example.com> <20020411181753.B29344@example.com> <20020411205342.GA293%j-morgan@example.com> <20020412094015.A3735@example.com> <20020412011528.GA6042@example.com>
- User-agent: Mutt/1.2.4i-jp0
On Fri, Apr 12, 2002 at 10:15:28AM +0900, Christopher SEKIYA wrote: > On Fri, Apr 12, 2002 at 09:40:15AM +0900, Matt Doughty wrote: > > > It seems an exploit is already in the wild. > > FWIW, the other *BSDs are not vulnerable. This was an old vulnerability > that got reintroduced in OpenBSD 2.9. > Added to that did you see the stupid sanity check they removed (aparently for the second time)? I would love to know what the developer in question was thinking. Fact is Open isn't using a different security model from the rest of so their 'better security' is just an illusion. They also aren't very good at auditing code if the recent bound checking errors in OpenSSH and this little botch up with mail are any indication. Don't buy the hype people. --Matt -- "Take away them collisions and the common channel and it's like Christianity without Christ." -Jim Breen (speaking about "full-duplex" Ethernet)
- Follow-Ups:
- Re: [tlug] OpenBSD local exploit
- From: Christopher SEKIYA
- References:
- Re: [tlug] Honeypots
- From: Christopher SEKIYA
- Re: [tlug] Honeypots
- From: Matt Doughty
- Re: [tlug] Honeypots
- From: Jack Morgan
- [tlug] OpenBSD local exploit
- From: Matt Doughty
- Re: [tlug] OpenBSD local exploit
- From: Christopher SEKIYA
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] OpenBSD local exploit
- Next by Date: Re: [tlug] OpenBSD local exploit
- Previous by thread: Re: [tlug] OpenBSD local exploit
- Next by thread: Re: [tlug] OpenBSD local exploit
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links