From owner-freebsd-current Sun Oct 7 1:13:22 2001 Delivered-To: freebsd-current@freebsd.org Received: from gull.mail.pas.earthlink.net (gull.mail.pas.earthlink.net [207.217.121.85]) by hub.freebsd.org (Postfix) with ESMTP id B753637B401 for ; Sun, 7 Oct 2001 01:13:19 -0700 (PDT) Received: from mindspring.com (dialup-209.244.104.16.Dial1.SanJose1.Level3.net [209.244.104.16]) by gull.mail.pas.earthlink.net (EL-8_9_3_3/8.9.3) with ESMTP id BAA09879; Sun, 7 Oct 2001 01:13:07 -0700 (PDT) Message-ID: <3BC00EC5.F0326FBE@mindspring.com> Date: Sun, 07 Oct 2001 01:13:57 -0700 From: Terry Lambert Reply-To: tlambert2@mindspring.com X-Mailer: Mozilla 4.7 [en]C-CCK-MCD {Sony} (Win98; U) X-Accept-Language: en MIME-Version: 1.0 To: Sheldon Hearn Cc: Kris Kennaway , Nate Williams , Lyndon Nerenberg , Bernd Walter , current@FreeBSD.ORG Subject: Re: PATCHES for Kris Kennaway to commit References: <44013.1002412762@axl.seasidesoftware.co.za> Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-freebsd-current@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG Sheldon Hearn wrote: > The change is not undefended. It's been made very clear from the > beginning that the security officer team sees the UUCP software as a > security liability, and would like the software "relegated" to ports so > as to limit the impact of vulnerabilities. The specific problem is the "--config" vulnerability noted on BugTraq, which ios easily fixed by "#ifdef'ing" it out. I understand that there have been a lot of bugs that have been listed as "FreeBSD bugs", when they were really software from third parties, but that's really no reason to be so hypersensitive about the distinction that FreeBSD becomes nothing more than the kernel and perl. -- Terry To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-current" in the body of the message