|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
XMCD v2.1 released (was: Security Problems in XMCD)
Xmcd Admin (xmcd
bazooka.amb.org)Mon, 25 Nov 1996 23:08:30 -0800
- Messages sorted by: [ date ][ thread ][ subject ][ author ]
- Next message: FreeBSD Security Officer: "FreeBSD Security Advisory: FreeBSD-SA-96:18.lpr"
- Previous message: Troy Bollinger: "lquerypv fix"
- In reply to: David J. Meltzer: "Security Problems in XMCD"
- Next in thread: David J. Meltzer: "Security Problems in XMCD 2.1"
This is to announce that XMCD 2.1 patchlevel 0 has been released
which fixes all of the issues previously raised by David Meltzer.
It also contains a number of other minor feature and functionality
enhancements. The new version may be obtained via the xmcd web page at:
http://sunsite.unc.edu/~cddb/xmcd/
Users of xmcd with older versions are encouraged to upgrade.
-Ti
--
\\ // XMCD - Motif CD player / CDA - Command line CD player
\\/ Ti Kan / AMB Research Laboratories
//\ E-mail: xmcd
amb.org
// \\ URL: http://sunsite.unc.edu/~cddb/xmcd/
David J. Meltzer <davem
iss.net> wrote:
> There are security holes in XMCD 2.0pl2 (and presumably all previous
> versions), a popular audio cd player for numerous unix platforms, which
> allow a user defined environment variable to overflow a fixed size buffer
> resulting in a complete compromise of system security on machines with XMCD
> installed suid root.
> [ ... description deleted ]
- Next message: FreeBSD Security Officer: "FreeBSD Security Advisory: FreeBSD-SA-96:18.lpr"
- Previous message: Troy Bollinger: "lquerypv fix"
- In reply to: David J. Meltzer: "Security Problems in XMCD"
- Next in thread: David J. Meltzer: "Security Problems in XMCD 2.1"