OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: youbin local root exploit + advisory

From: Jeremy C. Reed (reedreedmedia.net)
Date: Tue May 06 2003 - 12:05:58 CDT


On Tue, 6 May 2003, [iso-8859-1] Knud Erik Højgaard wrote:

> 5/5/03 - FreeBSD port maintainer notified
> 5/5/03 - FreeBSD port maintainer replies, bug is known, apparently no fix
> is planned at the moment

What about notifying the original developer?

What was the developer's response?

> 6/5/03 - public disclosure

At least you got FreeBSD to now mark it as FORBIDDEN. (Maybe submitting a
FreeBSD problem report would have gotten this done earlierr; I didn't find
one.)

What about Debian? And others that provide youbin?

   Jeremy C. Reed
   http://bsd.reedmedia.net/