Glibc glob patch

Bruce Dubbs bdubbs at swball.net
Sat Jan 12 14:16:42 PST 2002


Mark Binns wrote:

> On Sat, 12 Jan 2002, Bruce Dubbs wrote:
> 
>>I don't see a patch in the book, but I did find:
>>http://sources.redhat.com/ml/bug-glibc/2001-11/msg00109.html
>>
>>and its follow up:
>>
>>http://sources.redhat.com/ml/bug-glibc/2001-11/msg00110.html
>>
> 
> Ah ha! That looks like the one. Is that patch for their development (cvs)
> glibc or the 2.2.4 release? It may be worth including the patch in the
> book if the 2.2.4 release leaves you open to remote root exploits if
> you're running some ftpds.
> 
> Mark


I really don't know what release(s).  The email messages were on 
November and 2.2.4 was released (I think) in July.  I'm still using 
glibc 2.2.1 and the deleted code matches that release.  It looks like 
the code was submitted, but I don't know if it was accepted or not.

   -- Bruce


-- 
Unsubscribe: send email to listar at linuxfromscratch.org
and put 'unsubscribe lfs-security' in the subject header of the message



More information about the lfs-security mailing list