From owner-freebsd-security Tue Nov 21 1:13:33 2000 Delivered-To: freebsd-security@freebsd.org Received: from citusc17.usc.edu (citusc17.usc.edu [128.125.38.177]) by hub.freebsd.org (Postfix) with ESMTP id 838B037B4D7; Tue, 21 Nov 2000 01:13:29 -0800 (PST) Received: (from kris@localhost) by citusc17.usc.edu (8.11.1/8.11.1) id eAL9EQd96460; Tue, 21 Nov 2000 01:14:26 -0800 (PST) (envelope-from kris) Date: Tue, 21 Nov 2000 01:14:26 -0800 From: Kris Kennaway To: Trevor Johnson Cc: security-officer@FreeBSD.org, security@FreeBSD.org Subject: Re: New security policy for FreeBSD 3.x Message-ID: <20001121011426.A96416@citusc17.usc.edu> References: <20001121003406.A95525@citusc17.usc.edu> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="DocE+STaALJfprDB" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from trevor@jpj.net on Tue, Nov 21, 2000 at 04:02:13AM -0500 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org --DocE+STaALJfprDB Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Nov 21, 2000 at 04:02:13AM -0500, Trevor Johnson wrote: > > This is untrue - we were informed by Jouko Pynonnen on 2 Oct 2000, > > which is about the time it hit bugtraq, it was fixed 7 days later by > > the vendor and we imported it 2 days after that. You must be referring > > to some other problem. >=20 > It was only meant as an example, but: a buffer overflow bug in > libncurses, which had to do with malicious settings of the TERMCAP > environment variable, was reported in April on Bugtraq > (http://www.securityfocus.com/archive/1/56721), and FreeBSD was said to be > affected. I assumed that the recent ncurses advisory was supposed to > cover it. FreeBSD-SA-00:17.libmytinfo.asc Kris --DocE+STaALJfprDB Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (FreeBSD) Comment: For info see http://www.gnupg.org iEYEARECAAYFAjoaPPIACgkQWry0BWjoQKVjdQCgoDugiDxE2zpz2tGpum98ijkR 3JwAn0Q+QtpdYNllWUnbjBAW/5JVs5rm =HWN0 -----END PGP SIGNATURE----- --DocE+STaALJfprDB-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message