Subject: Re: Weird advisory
To: Xavier HUMBERT <xavier.humbert@xavhome.fr.eu.org>
From: Frederick Bruckman <fredb@immanent.net>
List: tech-pkg
Date: 12/26/2002 08:48:07
On Thu, 26 Dec 2002, Xavier HUMBERT wrote:

> What is the "unknown" vulnerability ?
>
> > Running /etc/security.local:
> > Package png-1.2.5nb1 has a unknown vulnerability, see
> > ftp://swrinde.nde.swri.edu/pub/png-group/archives/png-list.200212
>
> When you look kat the mentioned URL, there's no vulnerability discussed.

Oops, my goof. I copied and pasted from an earlier advisory, and
failed to account for the fact that there's no formal advisory, just
discussion on the png-implement list. [Andrew Brown pointed it out to
me last night, but inexplicably didn't fix it. 8-)] Try it now.

Frederick