Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 24 Jun 1999 17:40:38 -0500
From:      trix@gatekeep.net
To:        <ports@FreeBSD.ORG>
Cc:        <imp@FreeBSD.ORG>
Subject:   Re: hhp: Remote pine exploit. (fwd)
Message-ID:  <003a01bebe92$962a2680$69c9a1d0@mail.gatekeep.net>

next in thread | raw e-mail | index | archive | help
This is a multi-part message in MIME format.

------=_NextPart_000_0037_01BEBE68.AC3FEF60
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

They are saying any version to current 4.10 is Bugged....
I have not tried it, but it does say freebsd and BSD/i is
not protected from the latest bug.  Best thing to do, is update
your ports, and make deinstall ; make install pine (the ports
have 4.10 in them now)

*******************************************************************
Gate Keeper Technologies
Brandon Hicks System Administrator
bhicks@gatekeep.net - Personal
freebsd@gatekeep.net - FreeBSD Lists/Help
(903)882-9559
www.gatekeep.net
*******************************************************************

-----Original Message-----
From: Adrian Penisoara <ady@freebsd.ady.ro>
To: Igor Roshchin <igor@physics.uiuc.edu>
Cc: imp@FreeBSD.ORG <imp@FreeBSD.ORG>; ports@FreeBSD.ORG =
<ports@FreeBSD.ORG>
Date: Thursday, June 24, 1999 9:03 AM
Subject: Re: hhp: Remote pine exploit. (fwd)


>Hi,
>
>On Wed, 23 Jun 1999, Igor Roshchin wrote:
>
>>
>> Hello!
>>
>>
>> FYI. (in case you haven't seen this advisory yet)
>
> I remember there has been another similar exploit announced in =
February
>and the Pine people patched it soon after by disallowing use of the
>mailcap.. BTW, (I think) we can't be affected since we don't have a
>system-wide mailcap file.
>
>>
>> Also: is pine 3.96 effected by this ?
>
> That remains to be seen, although I don't believe it has the necessary
>features implemented.
>
> I'll check it out tommorow in detail, right now I've got network =
problems
>here and can't do a thing...
>
>>
>>
>> Regards,
>>
>> Igor
>>
>>
>
> Thanks,
> Ady (@freebsd.ady.ro)
>
>
>
>To Unsubscribe: send mail to majordomo@FreeBSD.org
>with "unsubscribe freebsd-ports" in the body of the message
>


------=_NextPart_000_0037_01BEBE68.AC3FEF60
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD W3 HTML//EN">
<HTML>
<HEAD>

<META content=3Dtext/html;charset=3Diso-8859-1 =
http-equiv=3DContent-Type>
<META content=3D'"MSHTML 4.72.3110.7"' name=3DGENERATOR>
</HEAD>
<BODY bgColor=3D#d8d0c8>
<DIV>They are saying any version to current 4.10 is Bugged....<BR>I have =
not=20
tried it, but it does say freebsd and BSD/i is<BR>not protected from the =
latest=20
bug.&nbsp; Best thing to do, is update<BR>your ports, and make deinstall =
; make=20
install pine (the ports<BR>have 4.10 in them=20
now)<BR><BR>*************************************************************=
******<BR>Gate=20
Keeper Technologies<BR>Brandon Hicks System Administrator<BR><A=20
href=3D"mailto:bhicks@gatekeep.net">bhicks@gatekeep.net</A> - =
Personal<BR><A=20
href=3D"mailto:freebsd@gatekeep.net">freebsd@gatekeep.net</A> - FreeBSD=20
Lists/Help<BR>(903)882-9559<BR><A=20
href=3D"http://www.gatekeep.net">www.gatekeep.net</A><BR>****************=
***************************************************<BR><BR>-----Original =

Message-----<BR>From: Adrian Penisoara &lt;<A=20
href=3D"mailto:ady@freebsd.ady.ro">ady@freebsd.ady.ro</A>&gt;<BR>To: =
Igor Roshchin=20
&lt;<A =
href=3D"mailto:igor@physics.uiuc.edu">igor@physics.uiuc.edu</A>&gt;<BR>Cc=
:=20
<A href=3D"mailto:imp@FreeBSD.ORG">imp@FreeBSD.ORG</A> &lt;<A=20
href=3D"mailto:imp@FreeBSD.ORG">imp@FreeBSD.ORG</A>&gt;; <A=20
href=3D"mailto:ports@FreeBSD.ORG">ports@FreeBSD.ORG</A> &lt;<A=20
href=3D"mailto:ports@FreeBSD.ORG">ports@FreeBSD.ORG</A>&gt;<BR>Date: =
Thursday,=20
June 24, 1999 9:03 AM<BR>Subject: Re: hhp: Remote pine exploit.=20
(fwd)<BR><BR><BR>&gt;Hi,<BR>&gt;<BR>&gt;On Wed, 23 Jun 1999, Igor =
Roshchin=20
wrote:<BR>&gt;<BR>&gt;&gt;<BR>&gt;&gt;=20
Hello!<BR>&gt;&gt;<BR>&gt;&gt;<BR>&gt;&gt; FYI. (in case you haven't =
seen this=20
advisory yet)<BR>&gt;<BR>&gt; I remember there has been another similar =
exploit=20
announced in February<BR>&gt;and the Pine people patched it soon after =
by=20
disallowing use of the<BR>&gt;mailcap.. BTW, (I think) we can't be =
affected=20
since we don't have a<BR>&gt;system-wide mailcap=20
file.<BR>&gt;<BR>&gt;&gt;<BR>&gt;&gt; Also: is pine 3.96 effected by =
this=20
?<BR>&gt;<BR>&gt; That remains to be seen, although I don't believe it =
has the=20
necessary<BR>&gt;features implemented.<BR>&gt;<BR>&gt; I'll check it out =

tommorow in detail, right now I've got network problems<BR>&gt;here and =
can't do=20
a thing...<BR>&gt;<BR>&gt;&gt;<BR>&gt;&gt;<BR>&gt;&gt;=20
Regards,<BR>&gt;&gt;<BR>&gt;&gt; =
Igor<BR>&gt;&gt;<BR>&gt;&gt;<BR>&gt;<BR>&gt;=20
Thanks,<BR>&gt; Ady (@freebsd.ady.ro)<BR>&gt;<BR>&gt;<BR>&gt;<BR>&gt;To=20
Unsubscribe: send mail to <A=20
href=3D"mailto:majordomo@FreeBSD.org">majordomo@FreeBSD.org</A><BR>&gt;wi=
th=20
&quot;unsubscribe freebsd-ports&quot; in the body of the=20
message<BR>&gt;<BR></DIV></BODY></HTML>

------=_NextPart_000_0037_01BEBE68.AC3FEF60--



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-ports" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?003a01bebe92$962a2680$69c9a1d0>