Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 24 Apr 2004 06:31:17 -0700
From:      Kris Kennaway <kris@obsecurity.org>
To:        Andy Wolf <andy.wolf@schwaben.de>
Cc:        freebsd-stable@freebsd.org
Subject:   Re: Sophos and compat3x dependency
Message-ID:  <20040424133116.GA29653@xor.obsecurity.org>
In-Reply-To: <408A6BB6.4000609@schwaben.de>
References:  <408A6BB6.4000609@schwaben.de>

next in thread | previous in thread | raw e-mail | index | archive | help

--VbJkn9YxBvnuCH5J
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sat, Apr 24, 2004 at 03:29:26PM +0200, Andy Wolf wrote:
> Hello,
>=20
> currently I am trying to install Sophos Anti Virus and found out that=20
> these binaries require FreeBSD 3.x compatibility. Now the misc/compat3x=
=20
> port ist marked FORBIDDEN because of two security vulnerabilities=20
> (FreeBSD-SA-03:08.realpath and FreeBSD-SA-03:05.xdr).
>=20
> Any idea how to proceed ? Contacting Sophos ?

That would be a good idea.  Try explaining the problem to them and
asking them to produce a 4.x binary.

> Waiting for a fixed compat3x ?

I wouldn't hold my breath on that.  It's been over 4 months and no-one
in the community has expressed interest in fixing the security
vulnerabilities in question in the 3.x branch.

Kris

--VbJkn9YxBvnuCH5J
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (FreeBSD)

iD8DBQFAimwkWry0BWjoQKURAqijAKDZIX1GU2IdpQBkCDavKFU54IxB9gCg7HdP
vGYyoBZUaCTkAmBlOuU3fYQ=
=Fha/
-----END PGP SIGNATURE-----

--VbJkn9YxBvnuCH5J--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040424133116.GA29653>