From owner-cvs-all Fri Sep 13 7:34:32 2002 Delivered-To: cvs-all@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D073A37B401; Fri, 13 Sep 2002 07:34:25 -0700 (PDT) Received: from gw.nectar.cc (gw.nectar.cc [208.42.49.153]) by mx1.FreeBSD.org (Postfix) with ESMTP id 5FB4A43E75; Fri, 13 Sep 2002 07:34:25 -0700 (PDT) (envelope-from nectar@nectar.cc) Received: from madman.nectar.cc (madman.nectar.cc [10.0.1.111]) by gw.nectar.cc (Postfix) with ESMTP id 06D6F38; Fri, 13 Sep 2002 09:34:25 -0500 (CDT) Received: by madman.nectar.cc (Postfix, from userid 1001) id A3CAF137B9F; Fri, 13 Sep 2002 09:34:24 -0500 (CDT) Date: Fri, 13 Sep 2002 09:34:24 -0500 From: "Jacques A. Vidrine" To: cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org Subject: Re: cvs commit: ports/mail/qmailadmin Makefile Message-ID: <20020913143424.GB56353@madman.nectar.cc> Mail-Followup-To: "Jacques A. Vidrine" , cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org References: <200209111859.g8BIxuxs074949@freefall.freebsd.org> <20020913135407.GC384@straylight.oblivion.bg> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20020913135407.GC384@straylight.oblivion.bg> User-Agent: Mutt/1.4i X-Url: http://www.celabo.org/ Sender: owner-cvs-all@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG On Fri, Sep 13, 2002 at 04:54:07PM +0300, Peter Pentchev wrote: > On Wed, Sep 11, 2002 at 11:59:56AM -0700, Jacques Vidrine wrote: > > nectar 2002/09/11 11:59:56 PDT > > > > Modified files: > > mail/qmailadmin Makefile > > Log: > > Setuid binary is exploitable. > > http://security-archive.merton.ox.ac.uk/bugtraq-200208/0117.html > > Er.. I believe that the security flaw that this refers to was fixed > prior to the release of qmailadmin-1.0.6, as stated in my message with > the commit that updated the port to 1.0.6; actually, that was my primary > reason for the port update :) > > I've removed the FORBIDDEN line now. Sorry about that ... I must have unwittingly been looking at an out-of-date repository, and then made the actual commit on Freefall. Or something. :-) Cheers, -- Jacques A. Vidrine http://www.celabo.org/ NTT/Verio SME . FreeBSD UNIX . Heimdal Kerberos jvidrine@verio.net . nectar@FreeBSD.org . nectar@kth.se To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe cvs-all" in the body of the message