Re: remotely exploitable buffer overflow

2006-03-22 Thread Bastian Blank
On Wed, Mar 22, 2006 at 12:08:03PM +1100, Geoff Crompton wrote: > Security focus list a remote buffer overflow vulnerability. > http://www.securityfocus.com/bid/17178 This is wrong. The buffer overflow is limited to local users with CAP_SYS_ADMIN. The relevant commit in the upstream repository is

Re: remotely exploitable buffer overflow

2006-03-22 Thread Moritz Muehlenhoff
Geoff Crompton wrote: > Security focus list a remote buffer overflow vulnerability. > http://www.securityfocus.com/bid/17178 > > I can't find a CVE for it yet, so I cant see if you've got it under > control on your subversion patch tracking page. It's the first time I've heard of that. Solar Desig

remotely exploitable buffer overflow

2006-03-21 Thread Geoff Crompton
Hi, Security focus list a remote buffer overflow vulnerability. http://www.securityfocus.com/bid/17178 I can't find a CVE for it yet, so I cant see if you've got it under control on your subversion patch tracking page. Do you think it likely that a DSA will get fast tracked for this? -- Geoff