OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Bugtraq archives for 4th quarter (Oct-Dec) 1998: Re: [Linux] klogd 1.3-22 buffer overflow

Re: [Linux] klogd 1.3-22 buffer overflow

Mike (tomainoHOME.COM)
Tue, 17 Nov 1998 18:51:00 -0800

First of all, I know this is a moderated group..  and this message is
all my oppinion and nothing really important.


Martin Schulze wrote:
>     When reporting security related bugs you should *always* try to
>     use the current version of a package instead of an ancient old
>     one.

Not every system uses the latest version of every piece of software. The
upkeep required to do that on most systems would be ridiculous. The need
for this list is to report bugs in software the readers might be using,
which is not always the latest version.

I don't think it is a reflection of poor skills if your software has a
bug reported on this list. No system is 100% bug free, the more you look
for bugs, the more you will find generally.



Mike.