[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-Disclosure] FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability
- To: Ron DuFresne <dufresne@winternet.com>
- Subject: Re: [Full-Disclosure] FreeRADIUS 0.9.2 "Tunnel-Password" attribute handling vulnerability
- From: David Maxwell <david@crlf.net>
- Date: Thu, 27 Nov 2003 15:12:04 -0500
On Thu, Nov 27, 2003 at 01:47:26PM -0500, David Maxwell wrote:
> What point is there in coordinating an announcement of an already
> published vulnerability? However, Alan provided a vendor statement to
> the researcher - who then did not include it in his post to other
> security lists.
A self-correction. I had been told the last portion by another party,
but didn't confirm it myself. The posting to Full Disclosure did include
a vendor statement.
Sorry about that.
--
David Maxwell, david@vex.net|david@maxwell.net -->
(About an Amiga rendering landscapes) It's not thinking, it's being artistic!
- Jamie Woods
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html