OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Re: ??: Re: aix __ bos.rte.printers __ format string vulnerability

From: Sergey Kuprin (Sergey.Kuprinwarehouse.ru)
Date: Fri Jan 09 2004 - 00:00:54 CST


so. because ibm's managed security service don't offer detailed description
of vulns.
i assume vuln presented by me is not the same posted by ibm service.

but as you suggest this bug needs closer investigation with latest package.

                                                                                                                                       
                      Jose Carlos Luna
                      Duran Кому: Sergey Kuprin <Sergey.Kuprinwarehouse.ru>
                      <lunaaditel.org Копия:
> Тема: Re: ??: Re: aix __ bos.rte.printers __ format string vulnerability
                                                                                                                                       
                      08.01.2004 21:32
                                                                                                                                       
                                                                                                                                       

En Thu Jan 08, 2004 at 12:43:14PM +0300, Sergey Kuprin
<Sergey.Kuprinwarehouse.ru> escribio:
>
> thanks for pointing me.
>
[..]

Someone has pointed me that IBM published another advisory last month about
the same bug!!:

http://www-1.ibm.com/services/continuity/recover1.nsf/mss/MSS-OAR-E01-2003.1600.1

(new one)

http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2003.0660.1

(old one)

So, you should try to investigate with the newest version of the
package. Maybe you were right!

Best Regards,

--
Jose Carlos Luna Duran UJI
lunaaditel.org / Jose.Carlos.Lunacern.ch
Office Tel. +41 22 76 71880