Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 24 Apr 2004 06:31:17 -0700
From:      Kris Kennaway <kris@obsecurity.org>
To:        Andy Wolf <andy.wolf@schwaben.de>
Cc:        freebsd-stable@freebsd.org
Subject:   Re: Sophos and compat3x dependency
Message-ID:  <20040424133116.GA29653@xor.obsecurity.org>
In-Reply-To: <408A6BB6.4000609@schwaben.de>
References:  <408A6BB6.4000609@schwaben.de>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
On Sat, Apr 24, 2004 at 03:29:26PM +0200, Andy Wolf wrote:
> Hello,
> 
> currently I am trying to install Sophos Anti Virus and found out that 
> these binaries require FreeBSD 3.x compatibility. Now the misc/compat3x 
> port ist marked FORBIDDEN because of two security vulnerabilities 
> (FreeBSD-SA-03:08.realpath and FreeBSD-SA-03:05.xdr).
> 
> Any idea how to proceed ? Contacting Sophos ?

That would be a good idea.  Try explaining the problem to them and
asking them to produce a 4.x binary.

> Waiting for a fixed compat3x ?

I wouldn't hold my breath on that.  It's been over 4 months and no-one
in the community has expressed interest in fixing the security
vulnerabilities in question in the 3.x branch.

Kris

[-- Attachment #2 --]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (FreeBSD)

iD8DBQFAimwkWry0BWjoQKURAqijAKDZIX1GU2IdpQBkCDavKFU54IxB9gCg7HdP
vGYyoBZUaCTkAmBlOuU3fYQ=
=Fha/
-----END PGP SIGNATURE-----

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040424133116.GA29653>