1 msgChoose the quote that matches your financial needs
2 msgabout install --reinstall for overwriting possi...
1 msgdhcp delivered subnet broadcast address: 255.25...
1 msgHey remember i told you about this Madeleine

Re: [SECURITY] [DSA 717-1] New lsh packages fix...
\ Jerome Lacoste (30 Apr 2005)

5 msghow to display the SSHd fingerprint
1 msgRe: [SECURITY] [DSA 719-1] New prozilla package...
19 msgFixing stupid PHP application design flaws
3 msgDns refresh
1 msgFROM MR. PAUL .
3 msgFIle access auditing
1 msgRe: [SECURITY] [DSA 715-1] New cvs packages fix...
1 msgTime may be running out -apx
1 msgCordula Sonnhalter heute nicht im Haus : [SECUR...
1 msgHi, everyone
2 msgsshd: Disable PAM if you do not want to use pas...
2 msgRe: [SECURITY] [DSA 713-1] New junkbuster packa...
1 msgSnort log stuff
3 msgslocate 2.6-1.3.3 fails to install
1 msgDoS vulnerability in postgrey - fixed, upgraded...
Subject:Re: [SECURITY] [DSA 717-1] New lsh packages fix severalvulnerabilities
Group:Debian-security
From:Jerome Lacoste
Date:30 Apr 2005


 
Hi,

> CAN-2003-0826
>
> Bennett Todd discovered a heap buffer overflow in lshd which could
> lead to the execution of arbitrary code.

This vulnerability was reported 18 months ago. Is it possible to know:
- why it wasn't fixed in the meantime
-how it was found out it hadn't been done?

If Debian was the only distrib late, should I consider this security
status Debian specific?

Jerome


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com