SECURITY BUG IN INTERACTIVE UNIX AND ESIX

Chip Salzenberg chip at tct.uucp
Sun Feb 24 09:25:16 AEST 1991


According to cpcahil at virtech.uucp (Conor P. Cahill):
>Yes ISC made a big mistake in letting this bug go.
>HOWEVER, they are trying to get a fix out as soon as they can.

After having let this bug go for over a year, we're supposed to be
UNDERSTANDING because THEY need TIME?

Render unto us a break.

>>Such security holes are intolerable.
>
>Yes we all agree on this, even ISC.  

Actually, ISC's and Everex's attitude is apparently:  "Such security
holes are intolerable -- *unless* we can keep them secret."  A slight
difference, there.
-- 
Chip Salzenberg at Teltronics/TCT      <chip at tct.uucp>, <uunet!pdn!tct!chip>
"It's not a security hole, it's a SECURITY ABYSS." -- Christoph Splittgerber
   (with reference to the upage bug in Interactive UNIX and Everex ESIX)



More information about the Comp.unix.sysv386 mailing list