Full Disclosure mailing list archives
Re: FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability
From: David Maxwell <david () crlf net>
Date: Thu, 27 Nov 2003 15:12:04 -0500
On Thu, Nov 27, 2003 at 01:47:26PM -0500, David Maxwell wrote:
What point is there in coordinating an announcement of an already published vulnerability? However, Alan provided a vendor statement to the researcher - who then did not include it in his post to other security lists.
A self-correction. I had been told the last portion by another party,
but didn't confirm it myself. The posting to Full Disclosure did include
a vendor statement.
Sorry about that.
--
David Maxwell, david () vex net|david () maxwell net -->
(About an Amiga rendering landscapes) It's not thinking, it's being artistic!
- Jamie Woods
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability S-Quadra Security Research (Nov 21)
- Re: FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability David Maxwell (Nov 21)
- Re: FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability Ron DuFresne (Nov 25)
- Re: FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability David Maxwell (Nov 27)
- Re: FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability David Maxwell (Nov 27)
- Re: FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability Ron DuFresne (Nov 27)
- Re: FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability Ron DuFresne (Nov 25)
- Re: FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability David Maxwell (Nov 21)
