Re: [SECURITY] [DSA 122-1] New zlib & other packages fix bufferoverflow

2002-03-12 Thread Chuck Peters
On Tue, 12 Mar 2002, Zephaniah E. Hull wrote: > On Tue, Mar 12, 2002 at 05:46:13PM +1100, Andrew Tait wrote: > > Unless your are going to dial into a malicious ISP, I doubt this will be a > > problem (AFAIK, but don't quote me). > > Or unless you happen to be a small ISP using pppd on the receivi

Re: [SECURITY] [DSA 122-1] New zlib & other packages fix bufferoverflow

2002-03-12 Thread Florian Weimer
Jor-el <[EMAIL PROTECTED]> writes: > > Doesnt dpkg also compile with a static zlib? Why does it not make > this list? At least on unstable, it does. /usr/bin/dpkg-deb: zlib configuration table, little endian, 32 bit /usr/bin/dpkg-deb: zlib inflate table, little endian (Tool is available a

Re: [SECURITY] [DSA 122-1] New zlib & other packages fix bufferoverflow

2002-03-11 Thread Chuck Peters
ii ppp2.4.1-0.bunk.2 Point-to-Point Protocol (PPP) daemon. How does this affect ppp servers running potato with the unofficial 2.4 packages provided by Adrian Bunk? Does anyone have any recommendations for fixing this potential exploit? Thanks, Chuck -- To UNSUBSCRIBE, email t

Re: [SECURITY] [DSA 122-1] New zlib & other packages fix bufferoverflow

2002-03-11 Thread Adam Heath
On Mon, 11 Mar 2002, Jor-el wrote: > > The zlib vulnerability is fixed in the Debian zlib package version > > 1.1.3-5.1. A number of programs either link statically to zlib or include > > a private copy of zlib code. These programs must also be upgraded > > to eliminate the zlib vulnerability. Th