From owner-freebsd-security Wed Nov 28 0:44:46 2001 Delivered-To: freebsd-security@freebsd.org Received: from nagual.pp.ru (pobrecita.freebsd.ru [194.87.13.42]) by hub.freebsd.org (Postfix) with ESMTP id 076C237B416 for ; Wed, 28 Nov 2001 00:44:43 -0800 (PST) Received: (from ache@localhost) by nagual.pp.ru (8.11.6/8.11.6) id fAS8iIQ32553; Wed, 28 Nov 2001 11:44:19 +0300 (MSK) (envelope-from ache) Date: Wed, 28 Nov 2001 11:44:17 +0300 From: "Andrey A. Chernov" To: Koga Youichirou Cc: mike@sentex.net, freebsd-security@FreeBSD.ORG Subject: Re: wu-ftpd ? Message-ID: <20011128084416.GA32507@nagual.pp.ru> References: <5.1.0.14.0.20011127210017.0545a5e0@192.168.0.12> <20011128.122552.45455442.y-koga@jp.FreeBSD.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20011128.122552.45455442.y-koga@jp.FreeBSD.org> User-Agent: Mutt/1.3.23.2i Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Wed, Nov 28, 2001 at 12:25:52 +0900, Koga Youichirou wrote: > Mike Tancsa : > > I guess the post below is relates to what was on bugtraq last week about > > the mysterious new wu-ftpd vulnerability. I still dont see anything on > > wu-ftpd's site about it. Is this something specific to LINUX then ? Anyone > > have any info ? > > Following is RedHat's patch: > > --- wu-ftpd/src/glob.c.sec Thu May 31 09:30:36 2001 > +++ wu-ftpd/src/glob.c Wed Nov 21 18:22:17 2001 > @@ -309,7 +309,7 @@ > if (lm >= restbufend) > return (0); > } It seems that this patch is over another patch and not for original 2.6.1 sources. Could you please provide cumulative patch compared to original sources? -- Andrey A. Chernov http://ache.pp.ru/ To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message