Re: patch for qpopper remote exploit bug

From: Steven Winikoff (smwat_private)
Date: Mon Jun 29 1998 - 09:26:04 PDT

  • Next message: Aaron D. Gifford: "Re: More problems with QPOPPER - <sigh>"

    >This can blow up -
    
    It certainly can. :-(
    
    Basically I was in too much of a hurry and misread the NetBSD man page
    for vsnprintf(), leading me to write a nice implementation (well, I
    think so :-) of an entirely incorrect design. :-(
    
    Incidentally, when that was first pointed out to me I attempted to say
    so on Bugtraq, in order to prevent further confusion; unfortunately that
    reply doesn't seem to have made it out to the list.
    
    I apologize for wasting your time, but I do appreciate your polite and
    helpful reply. :-)
    
         - Steven
    ________________________________________________________________________
    Steven Winikoff                | "The difference between the right word
    Concordia University           |  and the nearly right word is the
    Montreal, QC, Canada           |  difference between the lightning and
    smwat_private         |  the lightning bug."
    http://alcor.concordia.ca/~smw |                            - Mark Twain
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:01:05 PDT