Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: [ GLSA 200503-12 ] Hashcash: Format string vulnerability

Re: [ GLSA 200503-12 ] Hashcash: Format string vulnerability

From: Adam Back <adam_at_cypherspace.org>
Date: 7 Apr 2005 05:19:30 -0000
('binary' encoding is not supported, stored as-is) In-Reply-To: <87r7irrzne.fsf_at_evinrude.uhoreg.ca>

Hi

Two notes:

- the format string security bug is now fixed in hashcash-1.17

- Hubert is correct that the bug was not in hashcash-1.13, it was introduced in hashcash 1.14

Cheers

Adam

>Just to note, version 1.13 of hashcash (incidentally, the version that's
>in Debian testing) doesn't seem to be vulnerable, as it doesn't contain
>the buggy line that Travis found. I'm not sure exactly when the bug was
>introduced.
Received on Apr 07 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos