Re: [Debian-audit] bumprace

From: Ulf Härnhammar <Ulf.Harnhammar.9485_at_student.uu.se>
Date: Sun, 16 Jan 2005 20:02:22 +0100

Quoting Steve Kemp <steve_at_shellcode.org>:

> On Sun, Jan 16, 2005 at 03:01:17PM +0100, Ulf H?rnhammar wrote:
> > Bug #290706 reports some buffer overflows in bumprace when handling $HOME
> and
> > the ~/.bumprace file. Bumprace isn't setuid or setgid, so the bugs don't
> have
> > any security impact.
>
> This was already reported by me, (and fixed), in #203226.
>
> Looks like something got dropped by somebody....

Oops! I guess I should start searching the bugs page before auditing stuff. At
least it will remind them to patch it again.

-- 
Ulf Harnhammar
http://www.advogato.org/person/metaur/
Received on Sun Jan 16 2005 - 19:02:39 GMT

Mailing list overview.