Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 8 Sep 2001 21:57:04 -0700
From:      Kris Kennaway <kris@obsecurity.org>
To:        Ade Lovett <ade@FreeBSD.org>
Cc:        Kris Kennaway <kris@FreeBSD.org>, cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org
Subject:   Re: cvs commit: ports/net Makefile ports/net/freebsd-uucp Makefile distinfo pkg-comment pkg-descr pkg-plist
Message-ID:  <20010908215704.A40054@xor.obsecurity.org>
In-Reply-To: <20010908234628.H9547@FreeBSD.org>; from ade@FreeBSD.org on Sat, Sep 08, 2001 at 11:46:28PM -0500
References:  <200109090346.f893kDG99712@freefall.freebsd.org> <20010908234628.H9547@FreeBSD.org>

next in thread | previous in thread | raw e-mail | index | archive | help

--huq684BweRXVnRxX
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sat, Sep 08, 2001 at 11:46:28PM -0500, Ade Lovett wrote:
> On Sat, Sep 08, 2001 at 08:46:13PM -0700, Kris Kennaway wrote:
> >   Add freebsd-uucp 1.06.1, a portified version of the gnu/libexec/uucp
> >   tree currently in src/, in preparation for removing this infrequently=
-used
> >   set of tools out of the base system.
>=20
> When will we see the same treatment for the r-commands, /usr/games, etc..
> etc.. ?  Is this the first step on packaging up the entire system

You could think of it that way if you like.

> or simply a case of being able to say "it's a ports problem" when
> further security concerns are discovered with it?  </cynic>

It's a security risk we can't easily fix completely at this point in
time, and this is a way to compartmentalize the impact so all FreeBSD
systems aren't affected, but only those who choose to use it and know
the risks.  It's been a removal target for a long time since it's so
rarely used, and I really think it can be moved out without creating
undue hassles for administrators who do use it.

Kris

--huq684BweRXVnRxX
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (FreeBSD)
Comment: For info see http://www.gnupg.org

iD8DBQE7mvagWry0BWjoQKURAlfMAKCjaSMjUimiRZ6xLlX0b750OEaK+QCeJgY7
QO7ihtg6rYh6AMYhdSJg2fQ=
=goS0
-----END PGP SIGNATURE-----

--huq684BweRXVnRxX--

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe cvs-all" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010908215704.A40054>