[16210] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Tumbleweed Worldsecure (MMS) BLANK 'sa' account password vuln

daemon@ATHENA.MIT.EDU (JD Conley)
Sat Aug 12 01:12:30 2000

Mime-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 7bit
Message-Id:  <25C73987893CD211A3FD006008C02172615CBA@SERVER-CA>
Date:         Fri, 11 Aug 2000 14:32:05 -0700
Reply-To: JD Conley <jdc@MALIBUBOATS.COM>
From: JD Conley <jdc@MALIBUBOATS.COM>
To: BUGTRAQ@SECURITYFOCUS.COM

> Tumbeweed refuses to acknowledge this vulnerability, which
> caused major outrage
> among my customers.  Therefore, I have no choice but to go
> public about this
> vulnerability.

It seems the post to BUGTRAQ lit a fire under Tubleweed.  In today's
technical bulletin they linked to a patch for the vulnerabilty here:

http://thompson.tumbleweed.com/NewKB/bulletin/UPFiles/sa-official.htm

home help back first fref pref prev next nref lref last post