From owner-freebsd-security@FreeBSD.ORG Sat Dec 5 22:29:10 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 8626D1065672 for ; Sat, 5 Dec 2009 22:29:10 +0000 (UTC) (envelope-from ml@infosec.pl) Received: from v027580.home.net.pl (v027580.home.net.pl [89.161.156.148]) by mx1.freebsd.org (Postfix) with SMTP id C37E58FC08 for ; Sat, 5 Dec 2009 22:29:09 +0000 (UTC) Received: from localhost (HELO ?192.168.1.66?) (ml.freeside@home@127.0.0.1) by m094.home.net.pl with SMTP; Sat, 5 Dec 2009 22:02:33 -0000 Message-ID: <4B1AD86F.8090907@infosec.pl> Date: Sat, 05 Dec 2009 22:02:23 +0000 From: Michal User-Agent: Thunderbird 2.0.0.23 (X11/20091128) MIME-Version: 1.0 To: freebsd-security@freebsd.org References: <200912030930.nB39UdMK037494@freefall.freebsd.org> In-Reply-To: <200912030930.nB39UdMK037494@freefall.freebsd.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: FreeBSD Security Advisory FreeBSD-SA-09:15.ssl X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 05 Dec 2009 22:29:10 -0000 FreeBSD Security Advisories wrote: > b) Execute the following commands as root: > > # cd /usr/src > # patch < /path/to/patch > # cd /usr/src/secure/lib/libcrypto > # make obj && make depend && make includes && make && make install > > NOTE: On the amd64 platform, the above procedure will not update the > lib32 (i386 compatibility) libraries. On amd64 systems where the i386 > compatibility libraries are used, the operating system should instead > be recompiled as described in > > Don't quite understand - do we really have to rebuild and reinstall whole world on amd64 just to update these libraries? Rebuilding is not a problem here but reinstalling can be painful because of host-based IDS, custom chflags and so on. Looks like a terrible waste of resources. Is there a way to reinstall just these libraries or to get them from the net in a secure manner i.e. signed? Cheers. Michal -- "Lost time is never found again." -Benjamin Franklin