[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <Pine.LNX.4.43.0305060955150.1090-100000@pilchuck.reedmedia.net>
Date: Tue, 6 May 2003 10:05:58 -0700 (PDT)
From: "Jeremy C. Reed" <reed@...dmedia.net>
To: bugtraq@...urityfocus.com
Subject: Re: youbin local root exploit + advisory
On Tue, 6 May 2003, [iso-8859-1] Knud Erik Højgaard wrote:
> 5/5/03 - FreeBSD port maintainer notified
> 5/5/03 - FreeBSD port maintainer replies, bug is known, apparently no fix
> is planned at the moment
What about notifying the original developer?
What was the developer's response?
> 6/5/03 - public disclosure
At least you got FreeBSD to now mark it as FORBIDDEN. (Maybe submitting a
FreeBSD problem report would have gotten this done earlierr; I didn't find
one.)
What about Debian? And others that provide youbin?
Jeremy C. Reed
http://bsd.reedmedia.net/
Powered by blists - more mailing lists