From owner-freebsd-security  Tue Jan 21 08:18:41 1997
Return-Path: <owner-security>
Received: (from root@localhost)
          by freefall.freebsd.org (8.8.4/8.8.4) id IAA27345
          for security-outgoing; Tue, 21 Jan 1997 08:18:41 -0800 (PST)
Received: from kalypso.iqm.unicamp.br (kalypso.iqm.unicamp.br [143.106.13.10])
          by freefall.freebsd.org (8.8.4/8.8.4) with ESMTP id IAA27339
          for <security@freebsd.org>; Tue, 21 Jan 1997 08:18:37 -0800 (PST)
Received: (from vazquez@localhost) 
           by kalypso.iqm.unicamp.br (8.8.4/8.7.3/FreeBSD/2.1.5) id OAA19175 
           for security@freebsd.org; Tue, 21 Jan 1997 14:29:51 -0200 (EDT)
Received: from styx.iqm.unicamp.br (styx.iqm.unicamp.br [143.106.13.1]) 
           by kalypso.iqm.unicamp.br (8.8.4/8.7.3/FreeBSD/2.1.5) 
           with ESMTP id OAA19101 
           for <vazquez@kalypso.iqm.unicamp.br>; Tue, 21 Jan 1997 14:23:40 -0200 (EDT)
Received: from brimstone (brimstone.netspace.org [128.148.157.143]) 
           by styx.iqm.unicamp.br (8.8.4/8.7.3/FreeBSD/2.1.5) 
           with ESMTP id OAA17792 
           for <vazquez@IQM.UNICAMP.BR>; Tue, 21 Jan 1997 14:23:35 -0200 (EDT)
Received: from netspace.org ([128.148.157.6]) by brimstone.netspace.org with ESMTP id <35367-27020>; Tue, 21 Jan 1997 11:10:13 -0500
Received: from netspace.org (unknown@netspace [128.148.157.6]) by netspace.org (8.8.2/8.8.2) with SMTP id LAA20690; Tue, 21 Jan 1997 11:09:36 -0500
Received: from NETSPACE.ORG by NETSPACE.ORG (LISTSERV-TCP/IP release 1.8b) with
          spool id 2315798 for BUGTRAQ@NETSPACE.ORG; Tue, 21 Jan 1997 10:51:22
          +1900
Received: from netspace.org (unknown@netspace [128.148.157.6]) by netspace.org
          (8.8.2/8.8.2) with SMTP id KAA18463 for <BUGTRAQ@NETSPACE.ORG>; Tue,
          21 Jan 1997 10:50:23 -0500
Approved-By: ALEPH1@UNDERGROUND.ORG
Received: from burgundy.eecs.harvard.edu (dholland@burgundy.eecs.harvard.edu
          [140.247.60.165]) by netspace.org (8.8.2/8.8.2) with ESMTP id
          XAA18655 for <bugtraq@netspace.org>; Mon, 20 Jan 1997 23:25:46 -0500
Received: (from dholland@localhost) by burgundy.eecs.harvard.edu (8.7.3/8.6.9)
          id XAA00454 for bugtraq@netspace.org; Mon, 20 Jan 1997 23:25:48 -0500
          (EST)
X-Mailer: ELM [version 2.4 PL25]
MIME-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Approved-By:  David Holland <dholland@EECS.HARVARD.EDU>
Message-ID: <199701210425.XAA00454@burgundy.eecs.harvard.edu>
Date: 	Mon, 20 Jan 1997 23:25:48 -0500
Reply-To: David Holland <dholland@eecs.harvard.edu>
From: David Holland <dholland@eecs.harvard.edu>
Subject:      Re: talkd problem
To: Multiple recipients of list BUGTRAQ <BUGTRAQ@NETSPACE.ORG>
In-Reply-To:  <199701210246.TAA27525@zeus.theos.com> from "Theo de Raadt" at
              Jan 20, 97 07:46:28 pm
Sender: owner-security@FreeBSD.ORG
X-Loop: FreeBSD.org
Precedence: bulk

 > revision 1.4
 > date: 1996/07/17 23:41:10;  author: deraadt;  state: Exp;  lines: +10 -8
 > buffer overflow from dholland@hcs.HARVARD.EDU; could do with some cleanup?
 >  [...]
 >
 > I really like it when we get to fix a security hole 5 months before
 > everyone else.  "Everyone else" should do something about that.

'cept for us, of course. :-)

I *tried* to get the information out to people, but it's like pulling
teeth sometimes.

Anyone who's maintaining BSD user-level network tools and doesn't have
my fixes, please feel free to get in touch with me. This talkd thing
was one of the first things I found, and I've been racking up more in
the past few months. :-/

--
   - David A. Holland             |    VINO project home page:
     dholland@eecs.harvard.edu    | http://www.eecs.harvard.edu/vino