Re: [Full-Disclosure] FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability

From: David Maxwell (david_at_crlf.net)
Date: 11/27/03

  • Next message: n.teusink_at_planet.nl: "[Full-Disclosure] phpBB 2.06 search.php SQL injection"
    To: Ron DuFresne <dufresne@winternet.com>
    Date: Thu, 27 Nov 2003 15:12:04 -0500
    
    

    On Thu, Nov 27, 2003 at 01:47:26PM -0500, David Maxwell wrote:
    > What point is there in coordinating an announcement of an already
    > published vulnerability? However, Alan provided a vendor statement to
    > the researcher - who then did not include it in his post to other
    > security lists.

    A self-correction. I had been told the last portion by another party,
    but didn't confirm it myself. The posting to Full Disclosure did include
    a vendor statement.

    Sorry about that.

    -- 
    David Maxwell, david@vex.net|david@maxwell.net -->
    (About an Amiga rendering landscapes) It's not thinking, it's being artistic!
    					      - Jamie Woods
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: n.teusink_at_planet.nl: "[Full-Disclosure] phpBB 2.06 search.php SQL injection"
    Loading