Re: ecartis / listar PoC

From: John Madden (weez@freelists.org)
Date: 04/26/02


From: John Madden <weez@freelists.org>
To: KF <dotslash@snosoft.com>, vuln-dev@securityfocus.com, bugtraq@securityfocus.com
Date: Fri, 26 Apr 2002 08:14:38 -0500

On Wednesday 24 April 2002 08:56 pm, KF wrote:
> Heres some code for this post a while back ...
> http://online.securityfocus.com/archive/82/258763
> This is NOT the same issue in the my_strings.c there are MULTIPLE issues
> in ecartis still and the same goes for listar...
> This issue is a strcpy from argv to a fixed buffer .... nothing special.

Please see Ecartis' mailing list archives regarding these issues. They're
aware of the problems and are working to resolve them.

How about, instead of just telling us about there being multiple issues
and posting an exploit, you post a patch to help fix the issues?

Thanks,
  John

-- 
# John Madden  weez@freelists.org ICQ: 2EB9EA
# FreeLists, Free mailing lists for all: http://www.freelists.org
# UNIX Systems Engineer, Ivy Tech State College: http://www.ivytech.edu
# Linux, Apache, Perl and C: All the best things in life are free!



Relevant Pages

  • Re: ecartis / listar PoC
    ... Please see Ecartis' mailing list archives regarding these issues. ... instead of just telling us about there being multiple issues ...
    (Bugtraq)
  • [UNIX] Ecartis / Listar multiple vulnerabilities
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... administers mailing lists. ... dropping in Ecartis / Listar may lead to root compromise. ...
    (Securiteam)
  • OT/FOAK: Paging the morethanonecomputerorthosethattaketheirlaptopoutandaboutisti
    ... people un Usenet and on various mailing lists, ... the spare room, and even though I explained that I was e-mailing, ... But if I'm not connected directly to my ISP, I can't use their news ... without having to start fiddling about with multiple webmail accounts. ...
    (uk.rec.motorcycles)
  • [UNIX] Ecartis Contains Multiple Vulnerabilities
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... software package that administers mailing lists (similar to Majordomo and ... used by Ecartis' administrator. ...
    (Securiteam)
  • Re: Mail Rule TO: myuself only
    ... of several people in the TO line (multiple names). ... However, if you are on any mailing lists that you want to receive, they ... multiple names, partial matches, or blanks? ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)