Gentoo Archives: gentoo-dev

From: Don Seiler <rizzo@g.o>
To: Kumba <kumba@g.o>
Cc: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] gaim-0.75-r5 stable push
Date: Sun, 18 Jan 2004 20:27:54
Message-Id: 20040118202745.GA4742@linguo.lan.seiler.us
In Reply to: Re: [gentoo-dev] gaim-0.75-r5 stable push by Kumba
1 This is out of my already limited area of knowledge.
2
3 I'll need someone with some hardened expertise to tell me if this is
4 indeed an attack or exploit and something that we need to notify
5 upstream.
6
7 Don.
8
9 On Sun, Jan 18, 2004 at 03:25:52PM -0500, Kumba wrote:
10 >
11 > I've had reports of it locking up an Indy when logging into Yahoo. SGI
12 > mips machines are big-endian, btw.
13 >
14 > I also found this bug, and I wonder if the two are connected:
15 >
16 > Bugzilla Bug 37919
17 > net-im/gaim-0.75-r1 reports stack smashing attack when connecting to Yahoo
18 >
19 > Maybe what we are seeing is a stack-smash attack taking out big-endian
20 > machines? (well, most anyways).
21 >
22 >
23 > --Kumba
24 >
25 > --
26 > "Such is oft the course of deeds that move the wheels of the world:
27 > small hands do them because they must, while the eyes of the great are
28 > elsewhere." --Elrond
29 >
30 >
31 > --
32 > gentoo-dev@g.o mailing list
33 >
34 >
35
36 --
37 "Illegitimacy is something we should talk about in terms of not having it."
38
39 George W. Bush
40 May 20, 1996

Replies

Subject Author
Re: [gentoo-dev] gaim-0.75-r5 stable push Matthew Kennedy <mkennedy@g.o>