From: Kent Crispin <kent@songbird.com>
To: cypherpunks@toad.com
Message Hash: b551610c1bc9fcdeb7a63e04ba84dd0eb3be6f4aea4fa6a7e26bd24edaccee27
Message ID: <19970718182345.30146@bywater.songbird.com>
Reply To: <Pine.LNX.3.93.970718133319.604A-100000@shirley>
UTC Datetime: 1997-07-19 01:46:48 UTC
Raw Date: Sat, 19 Jul 1997 09:46:48 +0800
From: Kent Crispin <kent@songbird.com>
Date: Sat, 19 Jul 1997 09:46:48 +0800
To: cypherpunks@toad.com
Subject: Re: Censorware Summit Take II, from The Netly News
In-Reply-To: <Pine.LNX.3.93.970718133319.604A-100000@shirley>
Message-ID: <19970718182345.30146@bywater.songbird.com>
MIME-Version: 1.0
Content-Type: text/plain
On Fri, Jul 18, 1997 at 02:48:15PM -0700, Alan wrote:
>
> Get the new version of Lynx. (2.7?) It does a better job of handling
> frames.
You should get it anyway, because of serious security related bug:
Computer Incident Advisory Capability
___ __ __ _ ___
/ | /_\ /
\___ __|__ / \ \___
__________________________________________________________
INFORMATION BULLETIN
Lynx Temporary Files & LYDownload.c Vulnerabilities
July 16, 1997 16:00 GMT
Number H-82
______________________________________________________________________________
PROBLEM: Two vulnerabilities exist for Lynx: 1) temporary
files, and
2) LYDownload.c.
PLATFORM: All Unix or Unix-like systems running Lynx up to and including
version 2.7.1
DAMAGE: 1) May allow local users to gain root privileges.
2) This vulnerability may be exploited by anyone who
can provide
Lynx a carefully crafted URL.
SOLUTION: Apply patches or workarounds listed below.
[...]
--
Kent Crispin "No reason to get excited",
kent@songbird.com the thief he kindly spoke...
PGP fingerprint: B1 8B 72 ED 55 21 5E 44 61 F4 58 0F 72 10 65 55
http://songbird.com/kent/pgp_key.html
Return to July 1997
Return to ““William H. Geiger III” <whgiii@amaranth.com>”