Subject: Re: [PINE-CERT-20020301] OpenSSH off-by-one
To: None <tech-security@netbsd.org>
From: Joseph Frazee <frazee.23@osu.edu>
List: tech-security
Date: 03/07/2002 13:37:32
At 01:26 PM 3/7/2002, Steven M. Bellovin wrote:
>Absolutely. There are several other recent bugtraq postings that also
>merit either advisories or pkgsrc security warnings, such as the buffer
>overflows in cfsd and apache, and the ipsec forwarding problem.
I haven't really followed bugtraq closely until the past 4 or 5 months and
something about this doesn't sit with me well. This would make it nearly 7
days between appearance on bugtraq and "full disclosure". What can be done
to improve this?
Joe
Joseph Frazee
The OSU Libraries
UNIX Manager
e-mail: frazee.23@osu.edu
phone: (614) 688-5432
pager: (614) 201-2699