BugTraq
Re: poc zlib sploit just for fun :) Feb 27 2003 02:41PM
Ralf S. Engelschall (rse engelschall com)

In article <200302241751.25591.kelledin+BTQ (at) skarpsey.dyndns (dot) org [email concealed]> you wrote:

> [...]
> Attached below is a patch RK and I whipped up yesterday, after I
> caught wind of this problem sometime in the afternoon.
> [...]

Thanks for your efforts. We've reviewed your patch for inclusion into
our OpenPKG "zlib" package and discovered that your configure checks are
not quite correct. For instance, you're incorrectly putting a va_list
variable into a snprintf call in one check, etc. Additionally we've
stripped down in size the patch to gzio.c (you re-formatted existing
code, etc). See http://cvs.openpkg.org/openpkg-src/zlib/zlib.patch for
our derived version of your patch in case you're interested.

Ralf S. Engelschall
rse (at) engelschall (dot) com [email concealed]
www.engelschall.com

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus