[11410] in bugtraq

home help back first fref pref prev next nref lref last post

Re: [SECURITY] new version isdnutils fixes exploitable xmonisdn

daemon@ATHENA.MIT.EDU (Florian Weimer)
Wed Aug 18 07:57:20 1999

Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Message-Id:  <87vhaey39h.fsf@deneb.cygnus.qad.org>
Date:         Tue, 17 Aug 1999 14:56:26 +0200
Reply-To: Florian Weimer <fw@S.NETIC.DE>
From: Florian Weimer <fw@S.NETIC.DE>
X-To:         Aleph One <aleph1@UNDERGROUND.ORG>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  Aleph One's message of "Sat, 14 Aug 1999 12:08:25 -0700"

Aleph One <aleph1@UNDERGROUND.ORG> writes:

> We have received reports that the version of xmonisdn as distributed
> in the isndutils package from Debian GNU/Linux 2.1 has a security
> problem.

Note that other Linux distributions may be affected as well.
The makefile that comes with the (rather outdated) isdn4kutils betas
and that was in the isdn4linux CVS tree installed xmonisdn setuid root,
too (until Paul Slootman committed a fix at the beginning of August).

home help back first fref pref prev next nref lref last post