[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <4425EB31.4020007@linuxbox.org>
Date: Sun, 26 Mar 2006 03:15:29 +0200
From: Gadi Evron <ge@...uxbox.org>
To: Eric Allman <eric+bugtraq@...philic.com>
Cc: Theo de Raadt <deraadt@....openbsd.org>,
bugtraq@...urityfocus.com
Subject: Re: SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS,
Memory Jumps, Integer Overflow)
Eric Allman wrote:
>> I know the guy who exploited it. He's better than you think he is.
>
>
> I'm sorry, I was not trying to imply in any way that Mark was blowing
> smoke. I believe he can do it. Take my statement literally: /we/ don't
> /see/ how it can be practical. Perhaps I should have said "understand"
> instead of "see". The point was that this is not a trivial problem to
> exploit. But yes, I do believe it is real, and I think (hope) I made
> that clear in my message.
2 public exploits and counting.
Gadi.
Powered by blists - more mailing lists