vulnwatch
[Top] [All Lists]

Re: [VulnWatch] AFFLIB(TM): Time-of-Check-Time-of-Use File Race

To: vulnwatch@vulnwatch.org
Subject: Re: [VulnWatch] AFFLIB(TM): Time-of-Check-Time-of-Use File Race
From: VSR Advisories <advisories@vsecurity.com>
Date: Mon, 30 Apr 2007 07:34:42 -0400
Delivered-to: sp-com-lists@consult.net
Delivered-to: vulnwatch-list@securepoint.com
Delivered-to: mailing list vulnwatch@vulnwatch.org
Delivered-to: moderator for vulnwatch@vulnwatch.org
In-reply-to: <20070427174226.GD3392@sentinelchicken.org>
List-help: <mailto:vulnwatch-help@vulnwatch.org>
List-post: <mailto:vulnwatch@vulnwatch.org>
List-subscribe: <mailto:vulnwatch-subscribe@vulnwatch.org>
List-unsubscribe: <mailto:vulnwatch-unsubscribe@vulnwatch.org>
Mailing-list: contact vulnwatch-help@vulnwatch.org; run by ezmlm
References: <20070427174226.GD3392@sentinelchicken.org>
User-agent: Mutt/1.5.13 (2006-08-11)
This specific vulnerability is not exploitable due to the referenced
code not being executed.  I appologize for the misinformation.

Updates to each vulnerability can be found here:

http://www.vsecurity.com/bulletins/advisories/2007/afflib-toctou.txt
http://www.vsecurity.com/bulletins/advisories/2007/afflib-overflows.txt
http://www.vsecurity.com/bulletins/advisories/2007/afflib-shellinject.txt
http://www.vsecurity.com/bulletins/advisories/2007/afflib-fmtstr.txt

We are currently not aware of any additional exploitable flaws in
AFFLIB.

tim

<Prev in Thread] Current Thread [Next in Thread>