看板FB_security
標 題Re: multiple vulnerabilities in the cvs server code
發信站NCTU CSIE FreeBSD Server (Tue Sep 14 22:31:49 2004)
轉信站ptt!FreeBSD.csie.NCTU!not-for-mail
On Tue, 14 Sep 2004, Xin LI wrote:
>> Also, it would be nice if such an advisories advance kern.osreldate,
>> so auditfile could check this automatically; e.g., I have 4.9-RELEASE-p11,
>> which isn't vulnerable to this problem, but kern.osreldate is still 490000
>> there. If Security Officer bumps src/sys/conf/newvers.sh, why he doesn't
>> bump src/sys/sys/param.h?
>
> I think it is not applicable to bump param.h, as it represents an ABI change,
> which a security update should not introduce. (just my $0.02 :-)
Then it should be another possibility to get release "patch level" - maybe
by parsing kern.osrelease? In any case, it would be nice to add such a
check, so portaudit won't complain when base system isn't vulnerable.
Sincerely, Dmitry
--
Atlantis ISP, System Administrator
e-mail:
[email protected]
nic-hdl: LYNX-RIPE
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"