From owner-freebsd-security Tue Jun 19 4:11:39 2001 Delivered-To: freebsd-security@freebsd.org Received: from ringworld.nanolink.com (ringworld.nanolink.com [195.24.48.13]) by hub.freebsd.org (Postfix) with SMTP id C3BA337B408 for ; Tue, 19 Jun 2001 04:11:35 -0700 (PDT) (envelope-from roam@orbitel.bg) Received: (qmail 40629 invoked by uid 1000); 19 Jun 2001 11:10:02 -0000 Date: Tue, 19 Jun 2001 14:10:02 +0300 From: Peter Pentchev To: default013 - subscriptions Cc: freebsd-security@freebsd.org Subject: Re: question about glob patch (ftp exploit) Message-ID: <20010619141002.C40002@ringworld.oblivion.bg> Mail-Followup-To: default013 - subscriptions , freebsd-security@freebsd.org References: Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from default013subscriptions@hotmail.com on Tue, Jun 19, 2001 at 02:32:21AM -0500 Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Tue, Jun 19, 2001 at 02:32:21AM -0500, default013 - subscriptions wrote: > Hi again, > > (thanks for the help with the last one, one more... :) > > Okay, I attempted to setup the patch for the glob ftp exploit and it failed > when I tried to make/install it... I got various responses regarding why > this happened, and the one that makes the most sense to me is that it will > probably work if I just make buildworld instead. > > My question is... I am on a FreeBSD 4.1 box... does the output of this > patching look normal? I would have assumed it to patch a bit cleaner... I'm > just a little afraid that maybe the patch didn't take right for some > reason... (I did follow the current instructions from the security advisory. > Thanks again. Since there were no rejected chunks, yes, it did patch cleanly. The offsets were the result of lines added/removed from the files in question between 4.1 and 4.3. There was even one chunk which applied with a 'fuzz' (one or more context line were not exactly the same), but apparently the rest of the context was the same, and the lines changed were exactly the same, so there's no cause for alarm. G'luck, Peter -- If this sentence didn't exist, somebody would have invented it. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message