OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Brad (bradcomstyle.com)
Date: Tue Jan 22 2002 - 11:52:11 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    >Date: Tue, 22 Jan 2002 16:33:00 +1100
    >From: Edwin Groothuis <edwinmavetju.org>
    >To: g_463hotmail.com
    >Cc: bugtraqsecurityfocus.com
    >Subject: Re: remote buffer overflow in sniffit

    [snip]

    > * Non maintainer upload.
    > * [security] sn_logfile.c: Replaced sprintfs by snprintfs fixing a buffer
    > overflow (bugtraq).
    > * [security] sn_analyse.c: Limit length of TCP packets to the buffer
    > size (buffer overflow with MTU > 5000).
    >
    > -- Torsten Landschoff <torstendebian.org> Fri, 26 May 2000 08:40:14 +0200
    >
    >I assume Debian patches this, the FreeBSD port also applies these patches.
    >
    >Edwin

    The OpenBSD port applies this patch too.

    revision 1.9
    date: 2000/08/30 23:50:29; author: brad; state: Exp; lines: +13 -15
    upgrade to sniffit 0.3.7beta + Debian patches

    // Brad

    bradcomstyle.com
    bradopenbsd.org