Date: Tue, 20 May 2003 14:26:57 -0700 From: "David O'Brien" <obrien@FreeBSD.org> To: Oliver Lehmann <oliver@FreeBSD.org> Cc: ports-committers@FreeBSD.org Subject: Re: cvs commit: ports/sysutils/cdrtools Makefile ports/sysutils/cdrtools/files patch-libscg::scsiopen.c Message-ID: <20030520212657.GA71463@dragon.nuxi.com> In-Reply-To: <200305202033.h4KKXiLP044664@repoman.freebsd.org> References: <200305202033.h4KKXiLP044664@repoman.freebsd.org>
next in thread | previous in thread | raw e-mail | index | archive | help
On Tue, May 20, 2003 at 01:33:44PM -0700, Oliver Lehmann wrote: > FreeBSD ports repository > Modified files: > sysutils/cdrtools Makefile > Added files: > sysutils/cdrtools/files patch-libscg::scsiopen.c > Log: > Fix a securety issue which may cause a local root exploit > (if the cdrecord binary is suid 0). > For more information about this, feel free to take a look at > http://marc.theaimsgroup.com/?l=bugtraq&m=105285564307225&w=2 Why not just updated the port to use ftp://ftp.berlios.de/pub/cdrecord/alpha/cdrtools-2.01a14.tar.gz
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030520212657.GA71463>