From owner-freebsd-questions@FreeBSD.ORG Sat Nov 10 09:21:04 2007 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 4972616A417 for ; Sat, 10 Nov 2007 09:21:04 +0000 (UTC) (envelope-from aryeh.friedman@gmail.com) Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.229]) by mx1.freebsd.org (Postfix) with ESMTP id 024A913C4A3 for ; Sat, 10 Nov 2007 09:21:03 +0000 (UTC) (envelope-from aryeh.friedman@gmail.com) Received: by wx-out-0506.google.com with SMTP id i29so534576wxd for ; Sat, 10 Nov 2007 01:20:52 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=beta; h=domainkey-signature:received:received:message-id:date:from:user-agent:mime-version:to:cc:subject:references:in-reply-to:x-enigmail-version:content-type:content-transfer-encoding; bh=2XyUnvv12YNQgqf08pMPnD3sBLE0GhM5UX0CKJRk1Z0=; b=iLF2ReGuzcSD7r3Wn/kZzf8Lco2ptik7TZk1yZMBuAlwW37pFb7yg6MrzQuZy3+nh4wArldksPNRzVN98dMipbbnqPbKroY87gbLIQOEoF5bwHiSq6oUvTNRJ9ZgDXEeft/xRHkFW66MAu0zCOoMwj1iIwy77NY4TVzSmxjETc8= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:message-id:date:from:user-agent:mime-version:to:cc:subject:references:in-reply-to:x-enigmail-version:content-type:content-transfer-encoding; b=CTHeM8o7bwowi+nVu+ERcxm5Ddnp3rLZ3C02auAEfARrgehfn07Tu9C9b47ccHnTgkBXwX8/9mxacbE0cr2BH3nVIlSsdUkX12K7iFxT4r1REhooBU94XV0kJ8VrvYjqbnh8CeWVQeUTHRamMKoU5RMi6pbOpZuBEvqr/wYh4JE= Received: by 10.70.37.12 with SMTP id k12mr735119wxk.1194686451858; Sat, 10 Nov 2007 01:20:51 -0800 (PST) Received: from ?192.168.2.2? ( [67.85.89.184]) by mx.google.com with ESMTPS id m33sm869129ele.2007.11.10.01.20.49 (version=TLSv1/SSLv3 cipher=RC4-MD5); Sat, 10 Nov 2007 01:20:51 -0800 (PST) Message-ID: <473577E9.7030802@gmail.com> Date: Sat, 10 Nov 2007 04:20:41 -0500 From: "Aryeh M. Friedman" User-Agent: Thunderbird 2.0.0.6 (X11/20071109) MIME-Version: 1.0 To: zbigniew szalbot References: <473570FC.7070002@szalbot.homedns.org> <4735766A.2020806@gmail.com> <4735775B.2020105@szalbot.homedns.org> In-Reply-To: <4735775B.2020105@szalbot.homedns.org> X-Enigmail-Version: 0.95.5 Content-Type: text/plain; charset=ISO-8859-2 Content-Transfer-Encoding: 7bit Cc: freebsd-questions@freebsd.org Subject: Re: cups-base problem X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 10 Nov 2007 09:21:04 -0000 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 zbigniew szalbot wrote: > Hello, > > Aryeh M. Friedman pisze: >>> I am not sure I understand the message about remote execution >>> of arbitrary code. >> That is just saying that if the security issue is a problem for >> you don't upgrade (i.e. go ahead if you don't care). >> > Thanks but I think I now understand even less :) If a security > issue is a problem, don't upgrade??? My understanding of the issue is under some situations cups-base may allow an attacker to execute arbitary commands (not sure with what privs) > > Not sure also how one could go ahead? There is no option to > continue. The message appears and that's all. I am not given any > option. Remove the "FORBIDDEN=" line in the makefile - -- Aryeh M. Friedman Developer, not business, friendly http://www.flosoft-systems.com -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.4 (FreeBSD) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFHNXfoJ9+1V27SttsRAteSAKCeeXqAfsk+OgoLP9l/wZvvvMFhAwCeK1l1 Vv+r9ICUlVxTpvN+A8jv4xw= =3fNE -----END PGP SIGNATURE-----