Vulnerability Development mailing list archives

Re: Re: ??: Re: aix __ bos.rte.printers __ format string vulnerability


From: "Sergey Kuprin" <Sergey.Kuprin () warehouse ru>
Date: Fri, 9 Jan 2004 09:00:54 +0300


so. because ibm's managed security service don't offer detailed description
of vulns.
i assume vuln presented by me is not the same posted by ibm service.

but as you suggest this bug needs closer investigation with latest package.



                                                                                                                        
               
                      Jose Carlos Luna                                                                                  
               
                      Duran                    Кому:    Sergey Kuprin <Sergey.Kuprin () warehouse ru>                   
                  
                      <luna () aditel org         Копия:                                                                
                  
                      >                        Тема:    Re: ??: Re: aix __ bos.rte.printers __ format string 
vulnerability             
                                                                                                                        
               
                      08.01.2004 21:32                                                                                  
               
                                                                                                                        
               
                                                                                                                        
               



En Thu Jan 08, 2004 at 12:43:14PM +0300, Sergey Kuprin
<Sergey.Kuprin () warehouse ru> escribio:

thanks for pointing me.

[..]

Someone has pointed me that IBM published another advisory last month about
the same bug!!:

http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2003.1600.1

(new one)

http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0660.1

(old one)


So, you should try to investigate with the newest version of the
package. Maybe you were right!

Best Regards,

--
Jose Carlos Luna Duran  @ UJI
luna () aditel org / Jose.Carlos.Luna () cern ch
Office Tel. +41 22 76 71880






Current thread: