From owner-freebsd-hackers@FreeBSD.ORG Thu Dec 4 13:57:35 2003 Return-Path: Delivered-To: freebsd-hackers@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E259F16A4CE; Thu, 4 Dec 2003 13:57:35 -0800 (PST) Received: from hak.cnd.mcgill.ca (hak.cnd.mcgill.ca [132.216.11.133]) by mx1.FreeBSD.org (Postfix) with ESMTP id C995B43FA3; Thu, 4 Dec 2003 13:57:30 -0800 (PST) (envelope-from mat@hak.cnd.mcgill.ca) Received: from hak.cnd.mcgill.ca (localhost [127.0.0.1]) by hak.cnd.mcgill.ca (8.12.9/8.12.8) with ESMTP id hB4Lsj15080764; Thu, 4 Dec 2003 16:54:45 -0500 (EST) (envelope-from mat@hak.cnd.mcgill.ca) Received: (from mat@localhost) by hak.cnd.mcgill.ca (8.12.9/8.12.8/Submit) id hB4Lsjmt080763; Thu, 4 Dec 2003 16:54:45 -0500 (EST) Date: Thu, 4 Dec 2003 16:54:45 -0500 From: Mathew Kanner To: ork@k7-net.net Message-ID: <20031204215445.GR54011@cnd.mcgill.ca> References: <1070548976.3fcf47f0d36b6@webmail.k7-net.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1070548976.3fcf47f0d36b6@webmail.k7-net.net> User-Agent: Mutt/1.4.1i Organization: I speak for myself, operating in Montreal, CANADA X-Spam-Status: No, hits=0.0 required=5.0 tests=none autolearn=no version=2.60 X-Spam-Checker-Version: SpamAssassin 2.60 (1.212-2003-09-23-exp) on hak.cnd.mcgill.ca cc: freebsd-hackers@freebsd.org cc: freebsd-bugs@freebsd.org Subject: Re: kbdcontrol bug X-BeenThere: freebsd-hackers@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Technical Discussions relating to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 04 Dec 2003 21:57:36 -0000 On Dec 04, ork@k7-net.net wrote: > Hi! i found a bug in kbdcontrol, it's an buffer overflow, info and patch: > http://bsdroolz.port5.com/patch > Its not a serious security problem, just a bug, kbdcontrol is not suid. > Cya! Hello, Thank you. This problem was also reported in http://www.freebsd.org/cgi/query-pr.cgi?pr=52960 --Mat -- Applicants must also have extensive knowledge of UNIX, although they should have sufficiently good programming taste to not consider this an achievement. - MIT AI Lab job ad in the /Boston Globe/