Re: Accepted osh 1.7-13 (i386 source)

2005-05-27 Thread Joey Hess
Oohara Yuuma wrote: > [please Cc: to me because I'm not subscribed to the list] > > On Thu, 26 May 2005 20:16:31 -0400, > Joey Hess <[EMAIL PROTECTED]> wrote: > > Oohara Yuuma wrote: > [changelog of osh_1.7-13] > > Reviewed and approved for sarge. In the future please try to make sure > > security

Re: Accepted osh 1.7-13 (i386 source)

2005-05-27 Thread Oohara Yuuma
[please Cc: to me because I'm not subscribed to the list] On Thu, 26 May 2005 20:16:31 -0400, Joey Hess <[EMAIL PROTECTED]> wrote: > Oohara Yuuma wrote: [changelog of osh_1.7-13] > Reviewed and approved for sarge. In the future please try to make sure > security holes have an entry in the BTS. For

Re: Accepted osh 1.7-13 (i386 source)

2005-05-26 Thread Joey Hess
Oohara Yuuma wrote: >* urgency set to high because this version fixes a buffer overflow > that causes unauthorized privilege escalation (thanks to Charles > Stevenson > <[EMAIL PROTECTED]> for the bug report) >* main.c: s/strcpy/strncpy/ and s/strcat/strncat/ to avoid a buffer >