From owner-freebsd-security@FreeBSD.ORG Wed Oct 12 20:56:52 2005 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id BA94016A420 for ; Wed, 12 Oct 2005 20:56:52 +0000 (GMT) (envelope-from kris@obsecurity.org) Received: from elvis.mu.org (elvis.mu.org [192.203.228.196]) by mx1.FreeBSD.org (Postfix) with ESMTP id 6D53E43D45 for ; Wed, 12 Oct 2005 20:56:52 +0000 (GMT) (envelope-from kris@obsecurity.org) Received: from obsecurity.dyndns.org (elvis.mu.org [192.203.228.196]) by elvis.mu.org (Postfix) with ESMTP id 55A071A3C24; Wed, 12 Oct 2005 13:56:52 -0700 (PDT) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id 8A0AA511BC; Wed, 12 Oct 2005 16:56:51 -0400 (EDT) Date: Wed, 12 Oct 2005 16:56:51 -0400 From: Kris Kennaway To: Vladimir Terziev Message-ID: <20051012205651.GA91215@xor.obsecurity.org> References: <200510111202.j9BC2obf081876@freefall.freebsd.org> <434C427D.40501@netfence.it> <20051012111457.17eacc99.vlady@sun-fish.com> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="jRHKVT23PllUwdXP" Content-Disposition: inline In-Reply-To: <20051012111457.17eacc99.vlady@sun-fish.com> User-Agent: Mutt/1.4.2.1i Cc: freebsd-security@freebsd.org Subject: Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 12 Oct 2005 20:56:52 -0000 --jRHKVT23PllUwdXP Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Wed, Oct 12, 2005 at 11:14:57AM +0300, Vladimir Terziev wrote: >=20 > Ok, i think the FreeBSD team should isolate all statically linked ? > applications which are part of the operating system and which depend > on OpenSSL. They must be re-build (not the whole operating system) > in order OpenSSL changes to be applyed to them. AFAIK there are no statically linked openssl applications in the FreeBSD base system, unless someone has specifically compiled them that way on their own. Kris P.S. Please wrap your lines at 70 characters so that your emails may be easily read. --jRHKVT23PllUwdXP Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (FreeBSD) iD8DBQFDTXiSWry0BWjoQKURAju8AJ4y0iaW4BX8NDPPDLy2pSPNotykvwCgwVCX YJvK4RAptw0F3p2MuBgxOV8= =brzr -----END PGP SIGNATURE----- --jRHKVT23PllUwdXP--