Re: ipop3d (x2) / pine (x2) / Linux kernel (x2) / Midnight

From: Miguel de Icaza (miguelat_private)
Date: Mon Apr 05 1999 - 11:00:14 PDT

  • Next message: Marc: "Multiple WinGate Vulnerabilities[Tad late]"

    > 7. Midnight Commander 4.x bugs (x2)
    >
    > Still not fixed. Temporary files mc are created in insecure way, allowing
    > typical races. Also, entering directories containing $(...) somewhere
    > might result in execution of embeeded code.
    
    4.x barely tells me anything.  Code in the 4.x can mean anything in
    the last 18 months.  P
    
    There are two major code versions:
    
          4.1.xx: old, stable
          4.5.xx: new, stable
    
    I do not know of any problems in 4.5.xx.  The code does take
    appropiate steps to work around those problems.
    
    > Described days ago, dunno why it hasn't been patched.
    
    you might have described that to your shrink, or perhaps a frog
    sitting on a rock, but I never saw any detailed bug reports about
    this.
    
    miguel.
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:41:33 PDT