[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-Disclosure] unarj dir-transversal bug (../../../..)
- To: full-disclosure@xxxxxxxxxxxxxxxx
- Subject: Re: [Full-Disclosure] unarj dir-transversal bug (../../../..)
- From: evilninja <evilninja@xxxxxxx>
- Date: Tue, 12 Oct 2004 13:48:30 +0200
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
doubles@xxxxxxxx wrote:
> On Mon, 11 Oct 2004 16:29:40 -0700 evilninja <evilninja@xxxxxxx> wrote:
>
>>evil@sheep:~$ unarj x test.arj
>>ARJ32 v 3.10, Copyright (c) 1998-2004, ARJ Software Russia. [27
>>Jun 2004]
>
> arj != unarj! debian is stubido dist nd it pakage ''arj'' as ''unarj''!
um, actually i had to install a package called "unarj", obviously it's
from the same source package. i wonder why this is the case at all. when i
have "gzip", i don't _install_ "ungzip" too. but this is another discussion...
> real unarj 2.* inkl 2.65 latest are vunerabble!
how nice i have stubido gnu/linux running, not having such an "original"
version of unarj ;-)
- --
BOFH excuse #290:
The CPU has shifted, and become decentralized.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
iD8DBQFBa8SNC/PVm5+NVoYRAvJLAJ9khOeZwKhaSWGaKk5PNCmKdHFbTgCgmx0F
G8/N4bLBtRoSUMVmvSsm2nI=
=1qwI
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html