[osiris] Re: fwd: CVE-2006-3120: Arbitrary code execution in osiris

Jamie Wilkinson jaq at spacepants.org
Fri Jul 28 20:48:50 EDT 2006


This one time, at band camp, Jason 'XenoPhage' Frisvold wrote:
>Jamie Wilkinson wrote:
>> I've received this patch from the Debian Security Team, please apply it to
>> upstream as soon as possible.  It applies cleanly to 4.2.0 (excluding the
>> debian/changelog hunk, obviously).
>>   
>
>Quick question regarding this..  Is this a server or client bug?  Or 
>both?  Just wondering how quickly I need to update all clients..

All places where osiris uses logging ;-)

It's both in the master daemon and in the scan agent.



More information about the osiris mailing list