Full Disclosure mailing list archives

The last word on the Linux Slapper worm


From: pauls () utdallas edu (Schmehl, Paul L)
Date: Thu, 26 Sep 2002 15:20:18 -0500

I think adding the text you proposed below would be appropriate. :-)

Paul Schmehl (pauls () utdallas edu)
Department Coordinator
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/~pauls/


-----Original Message-----
From: Ben Laurie [mailto:ben () algroup co uk] 
Sent: Thursday, September 26, 2002 2:53 AM
To: Schmehl, Paul L
Cc: John.Airey () rnib org uk; full-disclosure () lists netsys com
Subject: Re: [Full-disclosure] The last word on the Linux Slapper worm

As I've pointed out elsewhere, patching old versions without changing 
the version number is so stupid it leaves me boggling. But I guess in 
future I'll write into advisories: "warning - your vendor may 
be such a 
moron that you can't tell whether you are vulnerable or not by the 
version number, so I advise building from source or switching to a 
vendor with a clue".


Current thread: