From owner-freebsd-security@FreeBSD.ORG Mon Nov 7 07:44:07 2005 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8856B16A420 for ; Mon, 7 Nov 2005 07:44:07 +0000 (GMT) (envelope-from jimmy@inet-solutions.be) Received: from mail.ihosting.be (vero.ihosting.be [83.217.81.43]) by mx1.FreeBSD.org (Postfix) with SMTP id 4EBE843D48 for ; Mon, 7 Nov 2005 07:44:05 +0000 (GMT) (envelope-from jimmy@inet-solutions.be) Received: (qmail 10575 invoked by uid 1033); 7 Nov 2005 07:47:03 -0000 Received: from jimmy@inet-solutions.be by excalibur.hyprotech.be by uid 1016 with qmail-scanner-1.20st (clamscan: 0.75. spamassassin: 2.63. Clear:RC:1(127.0.0.1):. Processed in 0.010222 secs); 07 Nov 2005 07:47:03 -0000 Received: from localhost (HELO vero.ihosting.be) (127.0.0.1) by mail.ihosting.be with SMTP; 7 Nov 2005 07:47:03 -0000 Received: (from jimmy@inet-solutions.be) by vero.ihosting.be (mini_sendmail/1.3.5 16nov2003); Mon, 07 Nov 2005 08:47:03 CET (sender jimmy@inet-solutions.be by using webserver vero.ihosting.be path /www/ihosting/horde.ihosting.be/imp - report abuse to abuse@boxke.be) Received: from 194.78.143.3 ([194.78.143.3]) by webmail.boxke.be (IMP) with HTTP for ; Mon, 7 Nov 2005 08:47:03 +0100 Message-ID: <1131349623.436f06779cbc1@webmail.boxke.be> Date: Mon, 7 Nov 2005 08:47:03 +0100 From: jimmy@inet-solutions.be To: "Simon L. Nielsen" References: <436E2F88.3010300@t-hosting.hu> <20051106204852.GB25399@ada.devbox.be> <20051106220942.GC904@zaphod.nitro.dk> In-Reply-To: <20051106220942.GC904@zaphod.nitro.dk> MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 8bit User-Agent: Internet Messaging Program (IMP) 3.2.3 X-Originating-IP: 194.78.143.3 Cc: freebsd-security@freebsd.org, =?iso-8859-1?b?S/Z2ZXNk4W4g?= =?iso-8859-1?b?R+Fib3I=?= , freebsd-questions@freebsd.org Subject: Re: What happened with portaudit? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 07 Nov 2005 07:44:07 -0000 Quoting "Simon L. Nielsen" : > On 2005.11.06 21:48:52 +0100, Jimmy Scott wrote: > > On Sun, Nov 06, 2005 at 05:30:00PM +0100, Kövesdán Gábor wrote: > > > Hello, > > > > > > One of my machines I got a report about 3 vulnerable packages (php4, > > > ruby, openssl) in tomorrows security run output, but in today's security > > > run output all of them disappeared, but nobody upgraded or removed the > > > affected packages. I reinstalled portaudit, refreshd its database, but > > > now it reports 0 affected pakages. The pkg_info command lists that three > > > packages, so they are still installed. Does anybody suspect what's wrong? > > > > I noticed the same, but didn't had the time to look for a possible > > answer on that question. > > It does seem to work for me now. Could people having this problem > please check the size of /var/db/portaudit/auditfile.tbz and try to > run portaudit -Fa to refetch the database and check again? > > For reference: > > [simon@zaphod:/tmp] ls -l /var/db/portaudit/auditfile.tbz > -r--r--r-- 1 root wheel 31762 6 Nov 22:40 /var/db/portaudit/auditfile.tbz > > There have been one previous report where a problem with the portaudit > database build resulted in an incomplete auditfile which was then > fixed after the next portaudit database rebuild. > > -- > Simon L. Nielsen > FreeBSD Security Team > Everything seems fine today, I can't check the size of the file from then since it's being run every night by periodic/security. If you are really interrested in the file I could restore it from a backup somehow, but it will be a lot of work. I should have checked it from the moment I noticed in the emails. Kind regards, Jimmy Scott ---------------------------------------------------------------- This message has been sent through ihosting.be To report spamming or other unaccepted behavior by a iHosting customer, please send a message to abuse@ihosting.be ----------------------------------------------------------------