From owner-freebsd-security@FreeBSD.ORG Tue Sep 16 09:53:04 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id DBBB016A4B3 for ; Tue, 16 Sep 2003 09:53:04 -0700 (PDT) Received: from util.inch.com (ns.inch.com [216.223.192.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id B1EFE43F85 for ; Tue, 16 Sep 2003 09:53:03 -0700 (PDT) (envelope-from spork@inch.com) Received: from shell.inch.com (www.inch.com [216.223.192.20]) h8GGr0NX074364; Tue, 16 Sep 2003 12:53:00 -0400 (EDT) (envelope-from spork@inch.com) Received: from shell.inch.com (localhost [127.0.0.1]) by shell.inch.com (8.12.8p1/8.12.8) with ESMTP id h8GGr0if022356; Tue, 16 Sep 2003 12:53:00 -0400 (EDT) (envelope-from spork@inch.com) Received: from localhost (spork@localhost)h8GGqxHF022351; Tue, 16 Sep 2003 12:52:59 -0400 (EDT) X-Authentication-Warning: shell.inch.com: spork owned process doing -bs Date: Tue, 16 Sep 2003 12:52:59 -0400 (EDT) From: Charles Sprickman To: Ng Pheng Siong In-Reply-To: <20030916164747.GA536@vista.netmemetic.com> Message-ID: <20030916125051.N60189@shell.inch.com> References: <20030916134347.GA30359@madman.celabo.org> <20030916161121.GA91300@madman.celabo.org> <20030916164747.GA536@vista.netmemetic.com> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: freebsd-security@freebsd.org Subject: Re: OpenSSH heads-up X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 16 Sep 2003 16:53:05 -0000 On Wed, 17 Sep 2003, Ng Pheng Siong wrote: > I'm a little confused. > > I'm running 4.8-RELEASE-p4. > > After cvsup'ing, I see patch-buffer.c in openssh-portable timestamped at 16 > Sep, whereas /usr/src/crypto/openssh shows files from 7 Apr and earlier. It hasn't hit 4.8 yet. You can try the following if you're in desperate need of the fix: ---- fetch http://www.openssh.com/txt/buffer.adv cd /usr/src/crypto/openssh patch < buffer.adv *then* follow the previous instructions for rebuilding ssh... Charles > A previous post in this thread said "(cd /usr/src/secure/lib/libssh; make; > blah blah)". Does this only apply to -STABLE and -CURRENT? > > Should I just install the port openssh-portable? Is this the raison d'etre > for openssh-portable? > > Do I need to drive down to the data centre now? (Rhetorical question to > self. ;-) > > Thanks. Cheers. > > -- > Ng Pheng Siong > > http://firewall.rulemaker.net -+- Manage Your Firewall Rulebase Changes > http://sandbox.rulemaker.net/ngps -+- Open Source Python Crypto & SSL > _______________________________________________ > freebsd-security@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org" >