[6061] in bugtraq

home help back first fref pref prev next nref lref last post

Re: KSR[T] Advisory #7: filter

daemon@ATHENA.MIT.EDU (hurtta+zz@OZONE.FMI.FI)
Mon Feb 2 17:07:53 1998

Date: 	Sun, 1 Feb 1998 16:18:56 +0200
Reply-To: hurtta+elm@ozone.FMI.FI
From: hurtta+zz@OZONE.FMI.FI
X-To:         ksrt@DEC.NET
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To:  <Pine.LNX.3.95.980129052902.1111B-100000@ogbanje.dec.net> from
              "KSR[T]" at "Jan 29, 98 05:29:22 am"

KSR[T]:
>                      The filter included in elm-2.4ME+37 also appears to
>                      be vulnerable to the "save_embedded_address()" attack,
>                      but not to the "get_filter_rules()" attack.

Note that any elm-2.4ME+ does _NOT_ install because security problems of it.

Changes of Elm2.4ME+ PL0 (25) compared to version Elm2.4 PL24 ME8b+
-------------------------------------------------------------------
<...>
        - Makefile now don't compile or install 'filter' because security
          problems in it.


/ Kari Hurtta

home help back first fref pref prev next nref lref last post