[17358] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Half Life dedicated server Patch

daemon@ATHENA.MIT.EDU (Shaun Meckler)
Thu Oct 26 13:50:15 2000

MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID:  <39F753B8.16C9E9D1@truckmaster.com>
Date:         Wed, 25 Oct 2000 15:42:16 -0600
Reply-To: Shaun Meckler <shaun@TRUCKMASTER.COM>
From: Shaun Meckler <shaun@TRUCKMASTER.COM>
To: BUGTRAQ@SECURITYFOCUS.COM

Patrick Oonk wrote:
> Someone pointed me to an announcement of a new Half Life patch which
> should be released next week and should fix the vulnerability described
> at http://www.securityfocus.com/bid/1799
>
> New features and fixes include:
> - Linux security issue resolved. <---------------------

  The patch was released earlier today. The linuxreadme.txt file
included in the release noted this as the only security related change:

- Rcon buffer overflow fixed.

It does not make any mention of the format string bug as mentioned in
'Tamandua Sekure Labs Security Advisory 2000-01'

home help back first fref pref prev next nref lref last post