|
|
|
View Notes By
|
|
|
|
Other Documents
|
|
|
|
|
Openwall GNU/*/Linux Information for VU#654390
| Date Notified | 06/12/2004 |
| Date Modified | 07/21/2004 10:33:59 AM |
| Status Summary | Unknown |
Vendor StatementOpenwall GNU/*/Linux (Owl) is not vulnerable to VU#317350 as we only ship dhcpd derived from version 3.0pl2. Since the very inclusion of the DHCP suite in Owl, we also include a patch which makes dhcpd run as its dedicated pseudo-user and in a chroot jail. In response to these new findings, we're adding another "hardening" patch which forces the use of snprintf() and vsnprintf() in all places where *sprintf() was used with non-constant string arguments.US-CERT AddendumThe CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|
 |