[<prev] [next>] [day] [month] [year] [list]
Message-ID: <web-20129968@bk3.webmaillogin.com>
Date: Fri, 13 Jul 2007 18:49:59 -0400
From: <edi.strosar@...nostne-novice.com>
To: "Full Disclosure" <full-disclosure@...ts.grok.org.uk>
Subject: Re: PIRS2007 local buffer overflow vulnerability
Dear 3APA3A,
you are absolutely right. Overwriting EIP does not
necessary mean that the application is exploitable.
Neither we claim that in our advisory. So, technically
speaking, consider this a "bug" or "buffer overflow
condition" rather than vulnerability.
Thanks God for semantics :)
Edi Strosar
(TeamIntell)
-- On 7/13/07, 3APA3A <3APA3A@...URITY.NNOV.RU> wrote:
> Please explain why is this "vulnerability" and not "just > the bug".
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists