Re: [SECURITY] [DSA-200-1] Samba buffer overflow

2002-11-25 Thread Olaf Meeuwissen
Matt Zimmerman <[EMAIL PROTECTED]> writes: > On Mon, Nov 25, 2002 at 08:24:45PM +0900, Olaf Meeuwissen wrote: > > > Hmm, from the version numbers (2.2.3a-6 to 2.2.3a-12) and changelog > > entries since the version in stable it looks as if this upgrade does a > > little more than just fix the se

Re: [SECURITY] [DSA-200-1] Samba buffer overflow

2002-11-25 Thread Olaf Meeuwissen
Matt Zimmerman <[EMAIL PROTECTED]> writes: > On Mon, Nov 25, 2002 at 08:24:45PM +0900, Olaf Meeuwissen wrote: > > > Hmm, from the version numbers (2.2.3a-6 to 2.2.3a-12) and changelog > > entries since the version in stable it looks as if this upgrade does a > > little more than just fix the se

Re: [SECURITY] [DSA-200-1] Samba buffer overflow

2002-11-25 Thread Matt Zimmerman
On Mon, Nov 25, 2002 at 08:24:45PM +0900, Olaf Meeuwissen wrote: > Hmm, from the version numbers (2.2.3a-6 to 2.2.3a-12) and changelog > entries since the version in stable it looks as if this upgrade does a > little more than just fix the security problem. Whatever happened to > just backport

Re: [SECURITY] [DSA-200-1] Samba buffer overflow

2002-11-25 Thread Matt Zimmerman
On Mon, Nov 25, 2002 at 08:24:45PM +0900, Olaf Meeuwissen wrote: > Hmm, from the version numbers (2.2.3a-6 to 2.2.3a-12) and changelog > entries since the version in stable it looks as if this upgrade does a > little more than just fix the security problem. Whatever happened to > just backport

Re: [SECURITY] [DSA-200-1] Samba buffer overflow

2002-11-25 Thread Olaf Meeuwissen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Saturday 23 November 2002 05:21, Wichert Akkerman wrote: > Package        : samba > Problem type   : remote exploit > Debian-specific: no > > Steve Langasek found an exploitable bug in the password handling > code in samba: when converting from DOS

Re: [SECURITY] [DSA-200-1] Samba buffer overflow

2002-11-25 Thread Olaf Meeuwissen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Saturday 23 November 2002 05:21, Wichert Akkerman wrote: > Package        : samba > Problem type   : remote exploit > Debian-specific: no > > Steve Langasek found an exploitable bug in the password handling > code in samba: when converting from DOS