From owner-freebsd-security Thu Aug 30 13:17: 1 2001 Delivered-To: freebsd-security@freebsd.org Received: from obsecurity.dyndns.org (adsl-63-207-60-54.dsl.lsan03.pacbell.net [63.207.60.54]) by hub.freebsd.org (Postfix) with ESMTP id 0A67137B405 for ; Thu, 30 Aug 2001 13:16:54 -0700 (PDT) (envelope-from kris@obsecurity.org) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id BDEBD66EA0; Thu, 30 Aug 2001 12:39:48 -0700 (PDT) Date: Thu, 30 Aug 2001 12:39:48 -0700 From: Kris Kennaway To: Rob Simmons Cc: freebsd-security@freebsd.org Subject: Re: FreeBSD Security Advisory FreeBSD-SA-01:58.lpd Message-ID: <20010830123948.A23605@xor.obsecurity.org> References: <200108301915.f7UJFv735421@freefall.freebsd.org> <20010830153246.K69164-100000@mail.wlcg.com> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="SLDf9lqlvOQaIe6s" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: <20010830153246.K69164-100000@mail.wlcg.com>; from rsimmons@wlcg.com on Thu, Aug 30, 2001 at 03:33:54PM -0400 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org --SLDf9lqlvOQaIe6s Content-Type: text/plain; charset=us-ascii Content-Disposition: inline On Thu, Aug 30, 2001 at 03:33:54PM -0400, Rob Simmons wrote: > I'm assuming that running lpd with -p to prevent it from opening a port is > also safe? I didn't see that mentioned in the advisory. It would probably make it safe from being *remotely* exploited. Local users who can submit jobs can still do it. Kris --SLDf9lqlvOQaIe6s Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE7jpaDWry0BWjoQKURAsSGAJ9hBHJeL5F5KfBqtgCo5A/PUiv4FwCeL5pu ohRW54SDcqu4XCRLgBzF7d4= =0MCz -----END PGP SIGNATURE----- --SLDf9lqlvOQaIe6s-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message