From owner-freebsd-ports@FreeBSD.ORG Thu Dec 16 06:59:57 2004 Return-Path: Delivered-To: freebsd-ports@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C35D816A4CE for ; Thu, 16 Dec 2004 06:59:57 +0000 (GMT) Received: from mail2out.barnet.com.au (mail2out.barnet.com.au [202.83.176.14]) by mx1.FreeBSD.org (Postfix) with ESMTP id DACEC43D54 for ; Thu, 16 Dec 2004 06:59:56 +0000 (GMT) (envelope-from edwin@mavetju.org) Received: by mail2out.barnet.com.au (Postfix, from userid 27) id C282D707449; Thu, 16 Dec 2004 17:59:55 +1100 (EST) X-Viruscan-Id: <41C1326B0000B59EB67797@BarNet> Received: from mail2-auth.barnet.com.au (mail2.barnet.com.au [202.83.176.13]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) Authority" (verified OK)) by mail2.barnet.com.au (Postfix) with ESMTP id 7F897707446; Thu, 16 Dec 2004 17:59:55 +1100 (EST) Received: from k7.mavetju (edwin-3.int.barnet.com.au [10.10.12.2]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) Certificate Authority" (verified OK)) by mail2-auth.barnet.com.au (Postfix) with ESMTP id 00E1C707443; Thu, 16 Dec 2004 17:59:54 +1100 (EST) Received: by k7.mavetju (Postfix, from userid 1001) id C123060DC; Thu, 16 Dec 2004 17:59:53 +1100 (EST) Date: Thu, 16 Dec 2004 17:59:53 +1100 From: Edwin Groothuis To: "Pedro F. Giffuni" Message-ID: <20041216065953.GH1435@k7.mavetju> References: <20041216010359.51904.qmail@web51604.mail.yahoo.com> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20041216010359.51904.qmail@web51604.mail.yahoo.com> User-Agent: Mutt/1.5.6i cc: freebsd-ports@FreeBSD.org Subject: Re: Security Exploits found in FreeBSD 4.10's ports tree. X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 16 Dec 2004 06:59:57 -0000 On Wed, Dec 15, 2004 at 05:03:59PM -0800, Pedro F. Giffuni wrote: > This made it to Slashdot today, but what they didn't mention is that the > xploits were found in FreeBSD 4.10's ports tree (at least the few that I've > checked): Another reason not to compile assembler sourcecode you get mailed from unknown sources with devel/nasm: I always knew it would bite me in the ankles! -- Edwin Groothuis | Personal website: http://www.mavetju.org edwin@mavetju.org | Weblog: http://weblog.barnet.com.au/edwin/