[39464] in bugtraq

home help back first fref pref prev next nref lref last post

Re: ekg insecure temporary file creation and arbitrary code execution

daemon@ATHENA.MIT.EDU (Adam Wysocki)
Wed Jul 6 19:14:33 2005

Date: Wed, 6 Jul 2005 22:05:09 +0200 (CEST)
From: Adam Wysocki <gophi@apcoh.org>
To: ZATAZ Audits <exploits@zataz.net>
Cc: vuldb@securityfocus.com, vuln@secunia.com, vuln@k-otik.com,
        moderators@osvdb.org, bugs@securitytracker.com,
        submissions@packetstormsecurity.org, news@securiteam.com,
        xforce@iss.net, bugtraq@securityfocus.com, vulnwatch@vulnwatch.org,
        full-disclosure@lists.grok.org.uk
In-Reply-To: <42CA2DDB.5030606@zataz.net>
Message-ID: <Pine.LNX.4.62.0507062200340.18529@avenger.gophi.rotfl.pl>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII

05.07.05 exploits@zataz.net wrote:

> Vendor informed: yes

Hi,

What do you understand by "Vendor informed"? We haven't received any 
email from you neither to private addresses nor ekg-users/ekg-devel 
mailing lists. Please also note that the script you pointed at is 
contributed by a third-party author and isn't part of ekg itself, 
neither is installed by default.

Greetings,

Adam Wysocki
ekg team

-- 
Adam Wysocki * http://www.gophi.rotfl.pl/ * GG 1234 * Fido 2:480/138

home help back first fref pref prev next nref lref last post