[Full-disclosure] Re: ekg insecure temporary file creation and arbitrary code execution

Adam Wysocki gophi at apcoh.org
Wed Jul 6 21:05:09 BST 2005


05.07.05 exploits at zataz.net wrote:

> Vendor informed: yes

Hi,

What do you understand by "Vendor informed"? We haven't received any 
email from you neither to private addresses nor ekg-users/ekg-devel 
mailing lists. Please also note that the script you pointed at is 
contributed by a third-party author and isn't part of ekg itself, 
neither is installed by default.

Greetings,

Adam Wysocki
ekg team

-- 
Adam Wysocki * http://www.gophi.rotfl.pl/ * GG 1234 * Fido 2:480/138



Full-Disclosure is hosted and sponsored by Secunia.