Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  news  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Tue, 21 Dec 2004 19:15:45 +0300
From: Solar Designer <solar@...nwall.com>
To: owl-users@...ts.openwall.com
Subject: Re: Linux 2.4.28-ow1 is out

Hi,

On Tue, Dec 21, 2004 at 12:33:24PM +0300, Ilya Andreiv wrote:
> And what about CAN-2004-1137 & CAN-2004-1016?

[ These are the IGMP and the SCM bugs, respectively. ]

> Is updated -ow patch will be coming or we should wait 2.4.29 kernel?

Honestly, I don't know whether it will be a 2.4.28-ow2 or 2.4.29-ow1.
That depends on how quick Marcelo is with putting out a 2.4.29 and on
whether other nasty bugs will be made public during that time.

I don't view these two bugs as terribly bad, requiring that I postpone
other work I had planned (including on some Owl bugs) and work on an
update immediately.  "The IGMP" does not affect most builds.  And "the
SCM" is just yet another local DoS.  (And there're other kernel bugs
which you did not ask about.)

These do need to get fixed indeed, but my time is too limited to spend
it without prioritizing things like I do now...

-- 
Alexander Peslyak <solar at openwall.com>
GPG key ID: B35D3598  fp: 6429 0D7E F130 C13E C929  6447 73C3 A290 B35D 3598
http://www.openwall.com - bringing security into open computing environments

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux