From owner-freebsd-security@FreeBSD.ORG Fri Dec 26 22:35:51 2014 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 93AC7D7B; Fri, 26 Dec 2014 22:35:51 +0000 (UTC) Received: from luigi.brtsvcs.net (luigi.brtsvcs.net [IPv6:2607:fc50:1000:1f00::2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 6C7042BF1; Fri, 26 Dec 2014 22:35:51 +0000 (UTC) Received: from chombo.houseloki.net (unknown [IPv6:2601:7:2580:181:21c:c0ff:fe7f:96ee]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by luigi.brtsvcs.net (Postfix) with ESMTPSA id B4A6B2D4F9B; Fri, 26 Dec 2014 22:35:42 +0000 (UTC) Received: from [IPv6:2601:7:2580:181:baca:3aff:fe83:bd29] (unknown [IPv6:2601:7:2580:181:baca:3aff:fe83:bd29]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by chombo.houseloki.net (Postfix) with ESMTPSA id 717FB1FA0; Fri, 26 Dec 2014 14:35:41 -0800 (PST) Message-ID: <549DE2B4.4080806@bluerosetech.com> Date: Fri, 26 Dec 2014 14:35:32 -0800 From: Darren Pilgrim Reply-To: freebsd-security@freebsd.org User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.3.0 MIME-Version: 1.0 To: Remko Lodder Subject: Re: FreeBSD Security Advisory FreeBSD-SA-14:31.ntp References: <20141223233310.098C54BB6@nine.des.no> <549C4D71.6030704@bluerosetech.com> <25260C1A-8230-47BD-9FAF-585D2B560303@FreeBSD.org> In-Reply-To: <25260C1A-8230-47BD-9FAF-585D2B560303@FreeBSD.org> Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit Cc: freebsd-security@freebsd.org X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 26 Dec 2014 22:35:51 -0000 On 12/25/2014 11:36 AM, Remko Lodder wrote: > >> On 25 Dec 2014, at 18:46, Darren Pilgrim >> wrote: >> >> On 12/23/2014 3:33 PM, FreeBSD Security Advisories wrote: >>> IV. Workaround >>> >>> No workaround is available, >> >> This was fixed in ports/net/ntp on Dec 20, so a workaround exists >> in the form of disabling the in-base version and installing the >> port. In the future, it would be helpful to mention such. > > We talk explicitly about the base system, not about ports. We never > mentioned them and I do not see a reason to start doing so. I don't understand why you wouldn't. It's a legitimate way of mitigating non-technical problems with system administration. For example, many organizations make scheduling a reboot harder/slower than scheduling the restart of a single service. Temporarily switching to the port in such cases is a very useful bandaid.