OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Reiner Steib (4uce.02.r.steib_at_gmx.net)
Date: Tue Oct 01 2002 - 06:41:03 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Tue, Oct 01 2002, Roman Drahtmueller wrote:

    > A new patch was defective and caused netscape and others to crash,
    > and we had to exchange it.
    >
    >> I'm a little confused about the changelog entries: Is it correct,
    >> that this package (for 7.1) ...
    >>
    >> ,----[ $ rpm -qp --changelog ./7.1/a1/glibc-2.2-22.i386.rpm|head -3]
    >> | * Fri Aug 02 2002 - kukuksuse.de
    >> |
    >> | - Check for overflow on multiplication in xdr_array().
    >> `----
    >>
    >> ... doesn't contain the fix, whereas this one (7.3) does?
    >>
    >> ,----[ $ rpm -qp --changelog ./7.3/a1/glibc-2.2.4-75.i386.rpm|head -3]
    >> | * Sat Aug 10 2002 - schwabsuse.de
    >> |
    >> | - Security fix for xdr_array.
    >
    > No need to be confused. Two different people have added different changes
    > to the logs while the changes addressed the same issue.

    Does ./7.1/a1/glibc-2.2-22.i386.rpm (dated August 6) contain the
    `correct' fix for the xdr_array-issue or the `defective' patch you
    mentioned?

    Bye, Reiner.

    -- 
           ,,,
          (o o)
    ---ooO-(_)-Ooo--- PGP key available via WWW   http://rsteib.home.pages.de/
    

    -- Check the headers for your unsubscription address For additional commands, e-mail: suse-security-helpsuse.com Security-related bug reports go to securitysuse.de, not here