From owner-freebsd-security@FreeBSD.ORG Mon Aug 4 15:10:35 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 30CE737B401 for ; Mon, 4 Aug 2003 15:10:35 -0700 (PDT) Received: from mail-in2.inet.tele.dk (mail-in2.inet.tele.dk [194.182.148.151]) by mx1.FreeBSD.org (Postfix) with ESMTP id 903B243F93 for ; Mon, 4 Aug 2003 15:10:34 -0700 (PDT) (envelope-from th@cogito.dk) Received: from THXP (0x50c791d8.odnxx4.adsl-dhcp.tele.dk [80.199.145.216]) by mail-in2.inet.tele.dk (Postfix) with SMTP id 51AA86567 for ; Tue, 5 Aug 2003 00:10:33 +0200 (CEST) Message-ID: <010701c35ad5$2e76d720$0201a8c0@THXP> From: "Troels Holm" To: References: <20030804210649.GC10339@madman.celabo.org><009d01c35acd$c9585230$0201a8c0@THXP> <20030804213203.GE10339@madman.celabo.org> Date: Tue, 5 Aug 2003 00:10:14 +0200 MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2800.1106 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106 Subject: Re: FreeBSD Security Advisory FreeBSD-SA-03:08.realpath X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 04 Aug 2003 22:10:35 -0000 Jacques A. Vidrine wrote: > The realpath.c that is distributed with OpenSSH-portable and found in > our CVS tree as /usr/src/crypto/openssh/openbsd-compat/realpath.c is > not used. Just for the record :=) What u say is that the advisory is in error and my "sftp-server" is _not_ affected? Or are you just saying that sftp isnt using the realpath.c from OpenSSH? Thanks, -- Troels Holm