Full Disclosure mailing list archives
Re: 1 year to fix a critical vuln [WAS: Heap Overflow in Oracle 9iAS .....]
From: Valdis.Kletnieks () vt edu
Date: Thu, 08 Apr 2004 12:57:03 -0400
On Thu, 08 Apr 2004 16:18:12 -0000, Hugh Mann <hughmann () hotmail com> said:
Which company will be first to wait 2 years to fix a vuln?
Already happened.
Subject: UnixWare 7.1.2 Open UNIX 8.0.0 UnixWare 7.1.1 UnixWare
7.1.2 : exploitable buffer overrun in metamail
Advisory number: CSSA-2003-SCO.15 Issue date: 2003 August 15
As far as I can tell, these are the same holes that Alan Cox fixed in the RedHat distrib version of metamail in June 1998.
Attachment:
_bin
Description:
Current thread:
- 1 year to fix a critical vuln [WAS: Heap Overflow in Oracle 9iAS .....] Hugh Mann (Apr 08)
- Re: 1 year to fix a critical vuln [WAS: Heap Overflow in Oracle 9iAS .....] Valdis . Kletnieks (Apr 08)