From owner-freebsd-security@FreeBSD.ORG Tue Aug 12 14:04:51 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id BF94A37B40F; Tue, 12 Aug 2003 14:04:51 -0700 (PDT) Received: from zephir.primus.ca (mail.tor.primus.ca [216.254.136.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8CF0343FA3; Tue, 12 Aug 2003 14:04:50 -0700 (PDT) (envelope-from leth@lethargic.dyndns.org) Received: from dialin-152-97.tor.primus.ca ([216.254.152.97] helo=lethargic.dyndns.org) by zephir.primus.ca with esmtp (TLSv1:DES-CBC3-SHA:168) (Exim 3.36 #3) id 19mgK0-0008R0-0A; Tue, 12 Aug 2003 17:04:49 -0400 Received: from lethargic.dyndns.org (localhost [127.0.0.1]) by lethargic.dyndns.org (8.12.9/8.12.9) with ESMTP id h7CL5aTm024174; Tue, 12 Aug 2003 17:05:37 -0400 (EDT) (envelope-from leth@lethargic.dyndns.org) Received: (from leth@localhost) by lethargic.dyndns.org (8.12.9/8.12.9/Submit) id h7CL5Z7Q024173; Tue, 12 Aug 2003 17:05:35 -0400 (EDT) Date: Tue, 12 Aug 2003 17:05:35 -0400 From: Jason Hunt To: "Simon L. Nielsen" Message-ID: <20030812210534.GA24139@lethargic.dyndns.org> References: <20030812085617.GA407@FreeBSD.org> <003501c360b0$6dad9970$9f8d2ed5@internal> <20030812113147.GA1022@FreeBSD.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20030812113147.GA1022@FreeBSD.org> User-Agent: Mutt/1.4.1i cc: "Devon H. O'Dell" cc: security@freebsd.org Subject: Re: realpath(3) et al X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 12 Aug 2003 21:04:52 -0000 On Tue, Aug 12, 2003 at 01:31:49PM +0200, Simon L. Nielsen wrote: > On 2003.08.12 11:02:16 +0200, Devon H. O'Dell wrote: > > Is there a list of these bugs available anywhere? If not, what software is > > recommended to import, keep track of, and document these bugs? > > The audit fixes from OpenBSD? I have no idea if they keep track of them > in some special way, but I think that integrating whem will require a > lot of looking at CVS commit logs and comparing code. http://www.openbsd.org/plus.html A lot easier than going through CVS logs :)