Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 1 Jul 2002 12:53:00 -0500
From:      "Jacques A. Vidrine" <nectar@freebsd.org>
To:        "Lachlan O'Dea" <odela01@ca.com>
Cc:        freebsd-security@freebsd.org
Subject:   Re: resolv and dynamic linking to compat libc
Message-ID:  <20020701175300.GG8128@madman.nectar.cc>
In-Reply-To: <3D1AA5F2.9020305@ca.com>
References:  <3D1AA5F2.9020305@ca.com>

next in thread | previous in thread | raw e-mail | index | archive | help

On Thu, Jun 27, 2002 at 03:43:14PM +1000, Lachlan O'Dea wrote:
> Hi,
> 
> With regard the resolv vulnerability, is there any issue with older 
> binaries that are linking against an older libc.so? For example, on my 
> box I have a /usr/lib/compat/libc.so.3. Will a make world fix this 
> library as well?

No, I'm afraid not.  libc.so.3 will not be rebuilt in the usual sense
of the word, thus leaving binaries that link against it vulnerable.
I don't have a solution for you at the moment, but once we've patched
RELENG_3 (FreeBSD 3.x), then perhaps we'll be able to get there.

Cheers,
-- 
Jacques A. Vidrine <n@nectar.cc>                 http://www.nectar.cc/
NTT/Verio SME          .     FreeBSD UNIX     .       Heimdal Kerberos
jvidrine@verio.net     .  nectar@FreeBSD.org  .          nectar@kth.se

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020701175300.GG8128>