From owner-freebsd-questions@FreeBSD.ORG Mon Sep 14 21:22:03 2009 Return-Path: Delivered-To: freebsd-questions@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 2F1F91065670 for ; Mon, 14 Sep 2009 21:22:03 +0000 (UTC) (envelope-from mikel.king@olivent.com) Received: from mail.olivent.com (mail.olivent.com [69.31.85.206]) by mx1.freebsd.org (Postfix) with ESMTP id 9A13C8FC0C for ; Mon, 14 Sep 2009 21:22:02 +0000 (UTC) Received: from [172.16.1.8] ([68.195.158.255]) (authenticated user mikel@olivent.com) by mail.olivent.com (Kerio MailServer 6.7.1) (using TLSv1/SSLv3 with cipher AES128-SHA (128 bits)); Mon, 14 Sep 2009 17:22:01 -0400 Message-Id: From: Mikel King To: dgoodin@theregister.com In-Reply-To: <4AAE95B2.5050409@sitpub.com> Mime-Version: 1.0 (Apple Message framework v936) Date: Mon, 14 Sep 2009 17:21:48 -0400 References: <4AAE95B2.5050409@sitpub.com> X-Mailer: Apple Mail (2.936) Content-Type: text/plain; charset=US-ASCII; format=flowed; delsp=yes Content-Transfer-Encoding: 7bit X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: media@FreeBSD.org, freebsd-questions@FreeBSD.org, press@FreeBSD.org Subject: Re: reporter on deadline seeks comment about reported security bug in FreeBSD X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 14 Sep 2009 21:22:03 -0000 On Sep 14, 2009, at 3:12 PM, Dan Goodin wrote: > Hello, > > Dan Goodin, a reporter at technology news website The Register. > Security > researcher Przemyslaw Frasunek says versions 6.x through 6.4 of > FreeBSD > has a security bug. He says he notified the FreeBSD Foundation on > August > 29 and never got a response. We'll be writing a brief article about > this. Please let me know ASAP if someone cares to comment. > > Kind regards, > > Dan Goodin > 415-495-5411 Hasn't 6.x been End Of Lifed? I mean considering that 8.0 is expected to be released either later this month or early next, and 6.x will be officially retired at that time, is it possible that this was overlooked? Personally I don't think it's ever good to overlook security, especially in the case of a root exploit. http://www.freebsd.org/releases/6.4R/announce.html Regards, Mikel King CEO, Olivent Technologies Senior Editor, Daemon News Columnist, BSD Magazine 6 Alpine Court, Medford, NY 11763 skype:mikel.king http://olivent.com http://mikelking.com http://twitter.com/mikelking