Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 05 May 1999 00:51:40 -0600
From:      Warner Losh <imp@harmony.village.org>
To:        "Jordan K. Hubbard" <jkh@zippy.cdrom.com>
Cc:        security@FreeBSD.ORG
Subject:   Re: [Jamie Rishaw <jamie@exodus.net>] FreeBSD 3.1 remote reboot exploit 
Message-ID:  <199905050651.AAA08231@harmony.village.org>
In-Reply-To: Your message of "Tue, 04 May 1999 22:39:04 PDT." <9230.925882744@zippy.cdrom.com> 
References:  <9230.925882744@zippy.cdrom.com>  

next in thread | previous in thread | raw e-mail | index | archive | help
-----BEGIN PGP SIGNED MESSAGE-----

In message <9230.925882744@zippy.cdrom.com> "Jordan K. Hubbard" writes:
: I can't speak for the others, but not being one of the security team
: folks I can say that I have no plans to say anything publically about
: this.

Being the security officer, I can say, without reservation, that I
have absolutely nothing to say about this publiclly.  I've sent mail
to Jamie and to bugtraq asking for an explaination.  Got zilch back so
far.  If and when there is a hole discovered, and the hole appears to
be being exploited or easily exploited, then an advisory will be
forth coming.  So far I have absolutely nothing to go on except
conjecture, which is not the basis for any statements or advisories.

In generaly, many DoS things are quietly fixed in -stable.  Sometimes
the folks that fix them know thay are fixing an implementation of what
Bruce likes to call panic(3), other times they don't.  There really
hasn't been anything of earth shaking importance that I've seen go
in.  Usually it is after the fixes go in that I see exploits start to
crop up...

Warner

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv
Comment: Processed by Mailcrypt 3.4, an Emacs/PGP interface

iQCVAwUBNy/qeNxynu/2qPVhAQGl2wP+IipljM57kSENjuxmyvBf43kwLOduJaRo
GBgGiAIgL1+M41lKPfr086Na0HCTOKgJB+bBCOsoBh5JknNc3WY3J9QoB+8IdY4B
GAFsAN0+Mq4PHPC7xikrYQyXJzLy9/D+uSGtT36ONhZJpvIKUCYeOPV4HcDCvz5g
/OnCFosMRU8=
=VAE+
-----END PGP SIGNATURE-----


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199905050651.AAA08231>