Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: What happened to the syslog bug ?

Re: What happened to the syslog bug ?

From: Gunnar Ingvi Thorisson <gunni_at_if.is>
Date: Tue, 25 Jun 1996 12:39:45 +0000

Hi there..

> In August last year 8LGM released an advisory warning about a syslog
> vulnerability. Something to do with a buffer overflow and passing commands
> to a remote site. The advisory said that exploit would not be released yet,
> in order to give time to vendors to issue patches. Now I understand that
> some vendors are pretty slow in acknowledging security problems but it
> sounds like they had enough time by now.
> Anyone considering posting details on this full disclosure list ?

the sendmail_wrapper.c was updated to prevent this bug, thats about it I
know about sendmail, if you're looking for cure, get this wrapper, it can
be found at any sendmail site. Hope it helps...

Best regards, Gunni...
gunni_at_if.is

=========================================================================
 Gunnar Ingvi Þórisson E-Mail address: gunni_at_if.is
 Kerfisstjóri, system administrator

 Íslensk forritaþróun hf.
 Suðurlandsbraut 4, IS-108 Reykjavík, Ísland
 Sími: (+354) 588-1511 Fax: (+354) 588-8728
=========================================================================
Received on Jun 25 1996

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos