[4402] in bugtraq

home help back first fref pref prev next nref lref last post

Re: A bug in Elm

daemon@ATHENA.MIT.EDU (Larry Schwimmer)
Mon May 5 02:01:00 1997

Date: 	Sun, 4 May 1997 17:22:53 -0700
Reply-To: Larry Schwimmer <rosebud@CYCLONE.STANFORD.EDU>
From: Larry Schwimmer <rosebud@CYCLONE.STANFORD.EDU>
X-To:         fflush@SUCKAH.ML.ORG
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To:  <Pine.LNX.3.96.970504115027.1220A-100000@suckah.ml.org> from
              "fflush" at May 4, 97 11:52:05 am

You (fflush) write:
> I ran into an Elm feature the other day which allows you to overwrite
> anyone's files

Upgrade your software; it is not current.

> The only version I tried this on is 2.4 PL24 (Linux), which I think is the
> latest one.

2.4 PL25 came out in December, 1995.  It may be found at:

ftp://ftp.myxa.com/pub/elm/elm2.4.tar.Z

2.4 PL25 is still the current release.  2.5 is in beta test.

The CERT vendor bulletins for this bug may be found at:

ftp://info.cert.org/pub/cert_bulletins/VB-95:10.elm
ftp://info.cert.org/pub/cert_bulletins/VB-95:10a.elm

                        yours,
                                Larry Schwimmer
                                schwim@cyclone.stanford.edu

home help back first fref pref prev next nref lref last post