[17387] in bugtraq
Re: Half Life dedicated server Patch
daemon@ATHENA.MIT.EDU (Nathan Woodcock)
Fri Oct 27 15:46:52 2000
Message-Id: <20001027124843.14864.qmail@securityfocus.com>
Date: Fri, 27 Oct 2000 12:48:43 -0000
Reply-To: Nathan Woodcock <nathan@NL.DEMON.NET>
From: Nathan Woodcock <nathan@NL.DEMON.NET>
To: BUGTRAQ@SECURITYFOCUS.COM
> > New features and fixes include:
> > - Linux security issue resolved. <---------------------
>
> The patch was released earlier today. The
linuxreadme.txt file
> included in the release noted this as the only
security related change:
>
> - Rcon buffer overflow fixed.
>
> It does not make any mention of the format string
bug as mentioned in
> 'Tamandua Sekure Labs Security Advisory 2000-01'
Leon Hartwig, the coder of the linux half-life patch
port, has confirmed in email on the hlds_linux mailing
list that this exploit was most definately fixed.