CAN-2004-0884 (cyrus-sasl)

Oliver Brakmann <[email protected]> Sat, 23 Oct 2004 17:10:57 +0200
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Hi,

gentoo reported two vulnerabilities in
<http://www.gentoo.org/security/en/glsa/glsa-200410-05.xml>.

One is fixed by upgrading to the latest release, which is 2.1.19. For
the other one, apply the attached patch.

What I find most disturbing is that the patch has been out there since
early July, in upstream's CVS even, while the advisory saw the light
only in early October! I don't know about you, but I think this is way
too long :-/

Bye,
Oliver
-- 
It's practically impossible to look at a   /\   #198843 @ http://counter.li.org
penguin and feel angry.     -- Joe Moore   \/   http://www.linuxfromscratch.org

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
cyrus-sasl-2.1.19-sasl_path_fix-1.patch.gz (application/x-gunzip, 633 B) - not displayed