|
BugTraq
[SECURITY] [DSA 1020-1] New flex packages fix insecure code generation Mar 27 2006 11:19PM Moritz Muehlenhoff (jmm debian org) (1 replies) Re: [SECURITY] [DSA 1020-1] New flex packages fix insecure code generation Mar 28 2006 02:08AM Matthew R. Dempsky (mrd alkemio org) (1 replies) |
|
Privacy Statement |
> On Tue, Mar 28, 2006 at 01:19:34AM +0200, Moritz Muehlenhoff wrote:
>> If you use code, which is derived from a vulnerable lex grammar in
>> an untrusted environment you need to regenerate your scanner with the
>> fixed version of flex.
>
> Do any Debian packages include such a vulnerable grammar? (If so, will
> rebuilt packages be provided?)
The packages including affected grammars or pregenerated code of that
kind have been identified and are being checked for exploitability.
Updates will be issued where necessary.
Cheers,
Moritz
[ reply ]