[Full-Disclosure] Re: Fwd: Re: [USN-52-1] vim vulnerability

From: Ciaran McCreesh (ciaranm_at_gentoo.org)
Date: 12/26/04

  • Next message: Paul Laudanski: "[Full-Disclosure] Re: New Santy-Worm attacks *all* PHP-skripts"
    Date: Sun, 26 Dec 2004 15:12:53 +0000
    To: Liu Die Yu <liudieyu@umbrella.name>
    
    
    
    

    On Sun, 26 Dec 2004 09:00:28 +0100 Sune Kloppenborg Jeppesen
    <jaervosz@gentoo.org> wrote:
    | ---------- Forwarded Message ----------
    |
    | Subject: Re: [USN-52-1] vim vulnerability
    | Date: Friday 24 December 2004 05:31
    | From: Liu Die Yu <liudieyu@umbrella.name>
    | To: Martin Pitt <martin.pitt@canonical.com>
    | Cc: ubuntu-security-announce@lists.ubuntu.com,
    | full-disclosure@lists.netsys.com, bugtraq@securityfocus.com
    |
    | the credit really should go to Georgi Guninski who said:
    <snip>

    This is a different unrelated vulnerability which has been fixed for a
    long time. The issues I found are not related to libcall*, rather they
    rely upon exploiting wildcards to make vim source arbitrary files.

    -- 
    Ciaran McCreesh : Gentoo Developer (Vim, Fluxbox, Sparc, Mips)
    Mail            : ciaranm at gentoo.org
    Web             : http://dev.gentoo.org/~ciaranm
    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Paul Laudanski: "[Full-Disclosure] Re: New Santy-Worm attacks *all* PHP-skripts"

    Relevant Pages

    • Re: Is it safe to use social securty number as intranet username? (long)
      ... You can ask, and I have, the credit agencies not to release your info ... Snip ... some states used to use your SSN ... I don't let go of my credit or debit card. ...
      (comp.security.misc)
    • Re: Is it safe to use social securty number as intranet username? (long)
      ... You can ask, and I have, the credit agencies not to release your info ... Snip ... some states used to use your SSN ... I don't let go of my credit or debit card. ...
      (comp.security.firewalls)
    • Re: doomed
      ... I'll give him credit, at least, for more than what I can give "three ducks" credit for. ... And, if the newspapers printed all sides of an issue, many more people would probably get upset or much more upset. ... Someone else countered that it wouldn't work as the conspiracists would find a way of showing that it was all faked. ...
      (sci.research.careers)
    • Re: Josh Bard....apologists?
      ... <snip of quite excellently rendered stats & comments> ... all of the credit for the 2004 Championship -- there's plenty of credit ... "Yes" to the above, but I think Epstein deserves at least a little more credit than what you're giving him, in that he had the capability to trade, cut, or not re-sign *some* of the players that had been acquired by his predecessors. ...
      (alt.sports.baseball.bos-redsox)
    • Re: Are/were the aussies really ever that good in the first place????
      ... >> Give a side some credit for being No. 1 for over 10 years. ... > from Australia making England look good. ...
      (rec.sport.cricket)