Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 22 May 2000 14:02:32 -0400
From:      "Crist J. Clark" <cjc@cc942873-a.ewndsr1.nj.home.com>
To:        Warner Losh <imp@village.org>
Cc:        freebsd-security@FreeBSD.ORG
Subject:   Re: The procfs Hole in 2.2.8-STABLE?
Message-ID:  <20000522140231.A35505@cc942873-a.ewndsr1.nj.home.com>
In-Reply-To: <200005220437.WAA92094@harmony.village.org>; from imp@village.org on Sun, May 21, 2000 at 10:37:11PM -0600
References:  <20000521140847.G96573@cc942873-a.ewndsr1.nj.home.com> <200005220437.WAA92094@harmony.village.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sun, May 21, 2000 at 10:37:11PM -0600, Warner Losh wrote:
> In message <20000521140847.G96573@cc942873-a.ewndsr1.nj.home.com> "Crist J. Clark" writes:
> : Am I to take it that 2.2.8-STABLE would be vulnerable? The following
> 
> Yes.  There are many vulnerabilities that were fixed in 3.x that
> haven't been back ported to 2.x.

Most of the security advisories since things stopped being back-ported
to 2.2.8 have been for ports. If I have the port, I remake a fixed
version, use an alternative, or live without. As for things in the
base system, the make vulnerability (FreeBSD-SA-00:01) doesn't really
scare me on a mailserver. That seems to be the only base system one of
any concequence in the advisories that has come up since they stopped
getting back-ported to 2.2.8.

Should I be concerned about these "many vulnerabilities?" Where are
they documented?
-- 
Crist J. Clark                           cjclark@home.com


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20000522140231.A35505>