Response to KF about Listar/Ecartis Vulnerability

From: Trish Lynch (trishat_private)
Date: Sat Apr 27 2002 - 07:35:09 PDT

  • Next message: Sten: "Re: apache + .htpasswd - bypass pwd check"

    Hello,
    	Thanks for putting a fire under me to get some of these issues
    fixed, unfortunately, while I am aware of these issues, I only really
    started to get to some of them in January, since then, outside concerns
    have taken over, and I've barely had enough time to get to fixing all of
    them.
    
    	Rest assured, I am going over the code line-by-line at this point,
    but its taking a while. The immediate issues have been fixed as of last
    night's snapshot (ecartis-1.0.0-snap20020427.tar.gz or
    ecartis-1.0.0-snap20020427.rpm).
    
    	I appreciate people being patient with us, and bringing forth
    specific issues, however I welcome anyone to email me directly with any
    specific issues before they go out to bugtraq so I can resolve them with
    no delays.
    
    	Thanks!
    
    -Trish Lynch
    
    (BTW, an Advisory *is* on its way, I'm waiting for the FreeBSD port to be
    committed)
    
    
    
    --
    Trish Lynch					trishat_private
    FreeBSD						The Power to Serve
    Ecartis Core Team				trishat_private
                       http://www.freebsd.org
    



    This archive was generated by hypermail 2b30 : Sat Apr 27 2002 - 11:02:33 PDT