[2812] in bugtraq
Re: What happened to the syslog bug ?
daemon@ATHENA.MIT.EDU (Gunnar Ingvi Thorisson)
Tue Jun 25 09:21:50 1996
Date: Tue, 25 Jun 1996 12:39:45 +0000
Reply-To: Bugtraq List <BUGTRAQ@NETSPACE.ORG>
From: Gunnar Ingvi Thorisson <gunni@if.is>
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>
In-Reply-To: <1996Jun25.130309.1604.93206@ntcit-mmta6.ntc.nokia.com> from
"Gadaix Emmanuel NTC/Bangkok" at Jun 25, 96 01:14:54 pm
Hi there..
> In August last year 8LGM released an advisory warning about a syslog
> vulnerability. Something to do with a buffer overflow and passing commands
> to a remote site. The advisory said that exploit would not be released yet,
> in order to give time to vendors to issue patches. Now I understand that
> some vendors are pretty slow in acknowledging security problems but it
> sounds like they had enough time by now.
> Anyone considering posting details on this full disclosure list ?
the sendmail_wrapper.c was updated to prevent this bug, thats about it I
know about sendmail, if you're looking for cure, get this wrapper, it can
be found at any sendmail site. Hope it helps...
Best regards, Gunni...
gunni@if.is
=========================================================================
Gunnar Ingvi ^srisson E-Mail address: gunni@if.is
Kerfisstjsri, system administrator
Mslensk forrita~rsun hf.
Supurlandsbraut 4, IS-108 Reykjavmk, Msland
Smmi: (+354) 588-1511 Fax: (+354) 588-8728
=========================================================================