From owner-freebsd-security Thu Sep 16 6:21:16 1999 Delivered-To: freebsd-security@freebsd.org Received: from alfik.ms.mff.cuni.cz (alfik.ms.mff.cuni.cz [195.113.19.71]) by hub.freebsd.org (Postfix) with ESMTP id 1A7A11546C for ; Thu, 16 Sep 1999 06:20:51 -0700 (PDT) (envelope-from mencl@nenya.ms.mff.cuni.cz) Received: from nenya.ms.mff.cuni.cz by alfik.ms.mff.cuni.cz; (8.8.8/v1.00/19990210.0854) id PAA13788; Thu, 16 Sep 1999 15:20:45 +0200 (MET DST) Received: from localhost (mencl@localhost) by nenya.ms.mff.cuni.cz (8.9.1b+Sun/8.9.1) with ESMTP id PAA03508; Thu, 16 Sep 1999 15:20:44 +0200 (MET DST) Date: Thu, 16 Sep 1999 15:20:44 +0200 (MET DST) From: "Vladimir Mencl, MK, susSED" To: Paulo Fragoso Cc: freebsd-security@FreeBSD.ORG Subject: Re: make world to FreeBSD-SA-99:05.fts In-Reply-To: Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org On Thu, 16 Sep 1999, Paulo Fragoso wrote: > Hi, > > On Wed, 15 Sep 1999, FreeBSD Security Officer wrote: > > > V. Solution > > > > Apply the following patches to libc and do a make world. Please also > > see the companion advisory FreeBSD-SA-99:04.core.asc in the advisories > > directory of our ftp site for details on the kernel portions of this > > fix. > > > > Index: lib/libc/gen/fts.c > > =================================================================== > > RCS file: /home/imp/FreeBSD/CVS/src/lib/libc/gen/fts.c,v > > We've a doubt. Can we aplly this patch and only make and make install on > /usr/src/lib/libc instead make world on /usr/src? It won't make a complete fix. find(1) is dynamically linked, so this ocurrence of the bug would be fixed, but rm(1), cp(1), mv(1) are all linked statically - they need to be recompiled with the new library... Vlada Mencl To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message