Vulnerabilities Research Group
Meeting Notes
Wednesday, July 22, 1998
tentative minutes; not yet approved
Present:
Matt Bishop,
Mike Fitzgrerald (notetaker),
Todd Heberlein,
Keith Herold,
David O'Brien,
Jeff Rowe,
Omar Vanegas,
Theresa White,
Meeting began at 11:00AM
- Previous Business
- none
- Presentation (Matt)
- Review of Intrusion Detection and Response Data Sharing Workshop
- Distributed executive summary (see proceedings or web page,
http://seclab.cs.ucdavis.edu/projects/idrds
- Vulnerabilities Database
Matt plans a release at the end of the summer,
of vulnerability data only (no attack data or signatures);
aim is to have about 60 entries in it.
- Bug of the week
Keith discussed an imapd vulnerability
having to do with buffer overflow. The problems is that imapd
takes 8K of data and tries to put it into a 1K buffer.
This version of imapd
was distributed with pine version 4.0, and a patch
has already been distributed
Meeting adjourned at 11:45AM
Send email to
bishop@cs.ucdavis.edu.
Matt Bishop
Department of Computer Science
University of California at Davis
Davis, CA 95616-8562
Page last modified on 8/4/98