Re: Mac OS 9 Idle Lock Bug

From: devbugsat_private
Date: Thu Nov 04 1999 - 11:41:57 PST

  • Next message: iarce: "Re: WFTPD v2.40 FTPServer remotely exploitable buffer overflow"

    Please include the line below in follow-up emails for this request.
    
    Follow-up:  1094807
    
    Hi Ben,
    
    The original issue, that was logged in as # 2404562 was found to be a duplicate of an
    already open issue, # 2405549. This information was reported back to the originator
    of the bug report,  Sean Sosik-Hamor.
    
    To ensure that the appropriate data is collected, please use the Bug Reporter when sending us your bug reports.   The Bug Reporter can be found at:
    
      <http://developer.apple.com/bugreporter>
    
    If the submitter is not currently an Apple developer, they may join our Online program at no charge.
    Addtional information can be found at this same website.
    
    Regards,
    
    Sean MacMillan
    Worldwide Developer Relations
    Apple Computer, Inc
    
    Send follow ups to devbugsat_private
    Send any comments on my work to devfeedbackat_private
    
    
    REQUEST ------------------------------------------------------------------------
    
      This message is in MIME format.  The first part should be readable text,
      while the remaining parts are likely unreadable without MIME-aware tools.
      Send mail to mimeat_private for more info.
    
    --W/nzBZO5zC0uMSeA
    Content-Type: TEXT/PLAIN; CHARSET=US-ASCII
    Content-ID: <Pine.GSO.4.10.9911040902052.17474at_private>
    
    We already have this listed in our database with Apple bug id # 2404562.
    Is this a mistake, or has there been two bug ids associated with this
    problem?
    
    We have the idle lock bug documented at:
    http://www.securityfocus.com/bid/745
    
    We also have another recent MacOS vuln, along similar lines, documented
    at:
    http://www.securityfocus.com/bid/756
    
    Any help would be greatly appreciated.
    
    Thank you,
    Ben Greenbaum
    Site Content Manager
    Security Focus
    http://www.securityfocus.com
    
    
    
    --W/nzBZO5zC0uMSeA
    Content-Type: MESSAGE/RFC822; CHARSET=US-ASCII
    Content-ID: <Pine.GSO.4.10.9911040902053.17474at_private>
    Content-Description:
    
    Return-Path: <>
    Delivered-To: aleph1at_private
    Received: (qmail 4456 invoked fro; 3 Nov 1999 22:37:25 -0000
    Received: from lists.securityfocus.com (207.126.127.68)
      by securityfocus.com with SMTP; 3 Nov 1999 22:37:25 -0000
    Received: from lists.securityfocus.com (lists.securityfocus.com [207.126.127.68])
    	by lists.securityfocus.com (Postfix) with ESMTP id 51A9C1F1BC
    	for <aleph1at_private>; Wed,  3 Nov 1999 13:51:25 -0800 (PST)
    Date:         Wed, 3 Nov 1999 13:51:25 -0800
    From: "L-Soft list server at LISTS.SECURITYFOCUS.COM (1.8d)" <LISTSERVat_private>
    Subject:      BUGTRAQ: approval required (296CE23E)
    To: Elias Levy <aleph1at_private>
    Message-Id: <19991103215125.51A9C1F1BCat_private>
    
    This  message was  originally submitted  by snrpat_private  to the
    BUGTRAQ list  at LISTS.SECURITYFOCUS.COM. You  can approve it using  the "OK"
    mechanism,  ignore it,  or repost  an edited  copy. The  message will  expire
    automatically and you do not need to  do anything if you just want to discard
    it. Please refer to  the list owner's guide if you are  not familiar with the
    "OK" mechanism; these instructions are being kept purposefully short for your
    convenience in processing large numbers of messages.
    
    ----------------- Original message (ID)6CE23E) (73 lines) -------------------
    Return-Path: <owner-bugtraqat_private>
    Delivered-To: bugtraqat_private
    Received: from securityfocus.com (securityfocus.com [207.126.127.66])
    	by lists.securityfocus.com (Postfix) with SMTP id 956F61F1BC
    	for <bugtraqat_private>; Wed,  3 Nov 1999 13:51:22 -0800 (PST)
    Received: (qmail 12920 invoked by alias); 3 Nov 1999 21:51:22 -0000
    Delivered-To: BUGTRAQat_private
    Received: (qmail 12904 invoked from network); 3 Nov 1999 21:51:17 -0000
    Received: from mail-out1.apple.com (17.254.0.52)
      by securityfocus.com with SMTP; 3 Nov 1999 21:51:17 -0000
    Received: from mailgate2.apple.com ([17.129.100.225])
    	by mail-out1.apple.com (8.9.3/8.9.3) with ESMTP id NAA03966
    	for <BUGTRAQat_private> Wed, 3 Nov 1999 13:51:16 -0800 (PST)
    Received: from scv3.apple.com (scv3.apple.com) by mailgate2.apple.com
     (Content Technologies SMTPRS 2.0.15) with ESMTP id <B0001443983at_private>;
     Wed, 03 Nov 1999 13:51:09 -0800
    Received: from kazon.corp.apple.com (kazon.corp.apple.com [17.32.112.16])
    	by scv3.apple.com (8.9.3/8.9.3) with ESMTP id NAA24193;
    	Wed, 3 Nov 1999 13:51:09 -0800 (PST)
    Received: (from snrp@localhost) by kazon.corp.apple.com (AIX4.3/UCB 8.8.8/8.8.8) id VAA93518; Wed, 3 Nov 1999 21:51:08 GMT
    Date: Wed, 3 Nov 1999 21:51:08 GMT
    Message-Id: <199911032151.VAA93518at_private>
    To: sshat_private, pnuttonat_private
    Cc: BUGTRAQat_private
    Subject: Re: Mac OS 9 Idle Lock Bug
    From: devbugsat_private
    Sender: snrpat_private
    
    Please include the line below in follow-up emails for this request.
    
    Follow-up:  1094807
    
    Hi Paul,
    
    Thank you for bringing this issue to our attention.  This is a known issue that is currently being investigated.  It has been filed into our bug database as ID # 2405549.
    
    I do not have a resolution for this issue at this time.
    
    In the future if you would like to check on any possible status on your issue, please send an email to devbugsat_private referring to the Bug ID #.
    
    Your input is greatly appreciated.
    
    Regards,
    
    Sean MacMillan
    Worldwide Developer Relations
    Apple Computer, Inc
    
    Send follow ups to devbugsat_private
    Send any comments on my work to devfeedbackat_private
    
    
    REQUEST ------------------------------------------------------------------------
    
    1094807
    
    Please could you let me know of the progress of resolving the above bug,
    as I wish to be able to upgrade to MacOS 9 but operate in a secure
    environment.
    --
    Paul Nutton, Systems Administrator, +44 (0)118 982 7028
    AWE plc, pnuttonat_private
    In a world without walls and fences, who needs windows and gates?
    
    DB REFERENCE -------------------------------------------------------------------
    
    TIME IN:			26-Oct-1999  07:43 PDT
    TIME OUT:		03-Nov-1999  14:32 PDT
    
    Copyright 1999, Apple Computer, Inc.
    
    SECURITY: NON-DISCLOSURE US
    
    --W/nzBZO5zC0uMSeA--
    
    DB REFERENCE -------------------------------------------------------------------
    
    TIME IN:			26-Oct-1999  07:43 PDT
    TIME OUT:		04-Nov-1999  12:25 PDT
    
    Copyright 1999, Apple Computer, Inc.
    
    SECURITY: NON-DISCLOSURE USE ONL
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:09:41 PDT