Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: [8lgm]-Advisory-14.UNIX.SCO-prwarn.12-Nov-1994
From: dsiebert () icaen uiowa edu (Doug Siebert)
Date: Tue, 29 Nov 1994 23:10:20 -0600 (CST)


Change that in: "how quickly Sun came with not-working patches"
Note too that the patch that finally fixed the /var/spool/mail
race conditions appeared months after the last 8lgm advisory.



The Sun patch fixed some of the problems and made the race harder to win.  It
also filled the particular hole that particular 8lgm script exposed.  Better
than a cryptic message from 8lgm saying "there is a bug in mail" and better
than hearing nothing at all from CERT until Sun believes they have the bug
fixed.  And if it takes several iterations for Sun to do this, and they
don't have whatever added pressure a widely-distributed exploit script adds,
this might a year or more for systems to be vulnerable to those who know
about this bug.  And with every passing day the chance someone else will
independly discover it increases...


-- 
Doug Siebert
dsiebert () isca uiowa edu



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]