[17041] in bugtraq
Re: BSD chpass
daemon@ATHENA.MIT.EDU (Warner Losh)
Wed Oct 4 03:08:12 2000
Message-Id: <200010040517.XAA33517@harmony.village.org>
Date: Tue, 3 Oct 2000 23:17:48 -0600
Reply-To: Warner Losh <imp@VILLAGE.ORG>
From: Warner Losh <imp@VILLAGE.ORG>
X-To: caddis <caddis@DISSENSION.NET>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To: Your message of "Wed, 04 Oct 2000 02:45:48 +1000."
<20001004024548.A516@dissension.net>
In message <20001004024548.A516@dissension.net> caddis writes:
: { "FreeBSD 4.0-RELEASE ", 167, 0x805023c, 0xbfbffc68, bsd_shellcode },
Just FYI, 4.1-RELEASE and newer aren't vulnerable. This problem was
fixed by us in our sweep of the tree in search of the format bugs that
came to light in late june.
Warner Losh
FreeBSD Security Officer