[Full-disclosure] Re: Linux kernel source archive vulnerable

2006-09-08 Thread Gerald (Jerry) Carter
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hadmut Danisch wrote: Hi, there's a severe vulnerability in the Linux kernel source code archives: It is my understanding that the permissions are intentionally set that way. This hash been discussed several times over the past year.

[Full-disclosure] Re: Linux kernel source archive vulnerable

2006-09-08 Thread Gerald (Jerry) Carter
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hadmut Danisch wrote: On Fri, Sep 08, 2006 at 10:55:32AM -0500, Gerald (Jerry) Carter wrote: It is my understanding that the permissions are intentionally set that way. yup, it's not accidentally, it set intentionally. But intention does

[Full-disclosure] Re: Linux kernel source archive vulnerable

2006-09-08 Thread Gerald (Jerry) Carter
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hadmut Danisch wrote: Really? Both means to do what is standing in the Makefile. Both is executing the Makefile. That's like saying ping should run as root since it reads /etc/hosts. If you cannot trust the kernel source to compile it as

[Full-disclosure] Re: Samba Internal Data Structures DOS Vulnerability Exploit

2006-07-21 Thread Gerald (Jerry) Carter
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Alexander, Name : Samba Internal Data Structures DOS Vulnerability Exploit Link : http://securitydot.net/xpl/exploits/vulnerabilities/articles/1175/exploit.html Date : 2006-07-21 Vulnerability :