From owner-freebsd-questions@FreeBSD.ORG Sat Nov 10 09:22:42 2007 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id D552A16A421 for ; Sat, 10 Nov 2007 09:22:42 +0000 (UTC) (envelope-from zbigniew@szalbot.homedns.org) Received: from lists.lc-words.com (lists.lc-words.com [83.19.156.210]) by mx1.freebsd.org (Postfix) with ESMTP id 82C9413C4D3 for ; Sat, 10 Nov 2007 09:22:42 +0000 (UTC) (envelope-from zbigniew@szalbot.homedns.org) Received: from localhost (localhost.szalbot.homedns.org [127.0.0.1]) by lists.lc-words.com (Postfix) with ESMTP id 603113F409; Sat, 10 Nov 2007 10:22:04 +0100 (CET) Received: from lists.lc-words.com ([127.0.0.1]) by localhost (szalbot.homedns.org [127.0.0.1]) (amavisd-maia, port 10026) with ESMTP id 91985-04; Sat, 10 Nov 2007 10:22:03 +0100 (CET) Received: from [192.168.0.150] (unknown [192.168.11.1]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: zbigniew@szalbot.homedns.org) by lists.lc-words.com (Postfix) with ESMTP id 7CBA03F407; Sat, 10 Nov 2007 10:22:03 +0100 (CET) Message-ID: <4735784C.9090505@szalbot.homedns.org> Date: Sat, 10 Nov 2007 10:22:20 +0100 From: zbigniew szalbot User-Agent: Thunderbird 2.0.0.6 (Windows/20070728) MIME-Version: 1.0 To: "Aryeh M. Friedman" References: <473570FC.7070002@szalbot.homedns.org> <4735766A.2020806@gmail.com> <4735775B.2020105@szalbot.homedns.org> <473577E9.7030802@gmail.com> In-Reply-To: <473577E9.7030802@gmail.com> Content-Type: text/plain; charset=ISO-8859-2; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Scanned: Maia Mailguard Cc: zbigniew szalbot , freebsd-questions@freebsd.org Subject: Re: cups-base problem X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 10 Nov 2007 09:22:42 -0000 Hello, Aryeh M. Friedman pisze: > > Aryeh M. Friedman pisze: > >>> I am not sure I understand the message about remote execution > >>> of arbitrary code. > >> That is just saying that if the security issue is a problem for > >> you don't upgrade (i.e. go ahead if you don't care). > >> > > Thanks but I think I now understand even less :) If a security > > issue is a problem, don't upgrade??? > > My understanding of the issue is under some situations cups-base may > allow an attacker to execute arbitary commands (not sure with what privs) > All clear now. Thanks a lot! > > > > Not sure also how one could go ahead? There is no option to > > continue. The message appears and that's all. I am not given any > > option. > > Remove the "FORBIDDEN=" line in the makefile > I appreciate it! Thank again! Zbigniew Szalbot