From owner-freebsd-security Tue Oct 1 11:52:35 2002 Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 4A49637B404 for ; Tue, 1 Oct 2002 11:52:32 -0700 (PDT) Received: from veldy.net (veldy-host33.dsl.visi.com [209.98.200.33]) by mx1.FreeBSD.org (Postfix) with ESMTP id CC0C043E3B for ; Tue, 1 Oct 2002 11:52:31 -0700 (PDT) (envelope-from veldy@veldy.net) Received: from VELDYLT (localhost [127.0.0.1]) by veldy.net (Postfix) with SMTP id BC85BA7; Tue, 1 Oct 2002 13:52:29 -0500 (CDT) Message-ID: <031201c2697b$b1de6070$8204dca7@northamerica.corp.microsoft.com> From: "Thomas T. Veldhouse" To: "Matt Piechota" , "Brett Glass" Cc: "Aaron Namba" , References: <4.3.2.7.2.20021001113225.034331b0@localhost> <4.3.2.7.2.20021001122135.0344e410@localhost> Subject: [OT] Re: Is FreeBSD's tar susceptible to this? Date: Tue, 1 Oct 2002 13:52:28 -0500 MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2800.1106 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org That has absolutely nothing to do with the license of any software product. That was very much picking on GPL for more selfish reasons than this tar security notice. ;) Tom Veldhouse ----- Original Message ----- From: "Brett Glass" To: "Matt Piechota" Cc: "Aaron Namba" ; Sent: Tuesday, October 01, 2002 1:23 PM Subject: RE: Is FreeBSD's tar susceptible to this? > At 11:46 AM 10/1/2002, Matt Piechota wrote: > > >Fearing the off-topic avalanche that's going to come of this... > > > >Why the GPL? It would have been just as likely to happen in BSD tar, > > It would be less likely, because the BSDs have more peer review and > more careful auditing. > > >except you'd have lots of people with their own patches that no one else > >could see. > > Define "lots of people." When either FreeBSD, NetBSD, OpenBSD, or Darwin > is patched, the others will follow. > > --Brett > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-security" in the body of the message > To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message