From owner-freebsd-security Mon Jul 8 7:41:57 2002 Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 786A137B400; Mon, 8 Jul 2002 07:41:54 -0700 (PDT) Received: from gw.nectar.cc (gw.nectar.cc [208.42.49.153]) by mx1.FreeBSD.org (Postfix) with ESMTP id DFC7943E42; Mon, 8 Jul 2002 07:41:53 -0700 (PDT) (envelope-from nectar@nectar.cc) Received: from madman.nectar.cc (madman.nectar.cc [10.0.1.111]) by gw.nectar.cc (Postfix) with ESMTP id 0334861; Mon, 8 Jul 2002 09:41:53 -0500 (CDT) Received: from madman.nectar.cc (localhost [IPv6:::1]) by madman.nectar.cc (8.12.3/8.12.3) with ESMTP id g68Efq0O023428; Mon, 8 Jul 2002 09:41:52 -0500 (CDT) (envelope-from nectar@madman.nectar.cc) Received: (from nectar@localhost) by madman.nectar.cc (8.12.3/8.12.3/Submit) id g68EfqYJ023427; Mon, 8 Jul 2002 09:41:52 -0500 (CDT) Date: Mon, 8 Jul 2002 09:41:52 -0500 From: "Jacques A. Vidrine" To: Akinori MUSHA Cc: security-team@FreeBSD.org, security@FreeBSD.org Subject: Re: cvs commit: src/lib/libc/net gethostbydns.c getnetbydns.c name6.c Message-ID: <20020708144152.GB23377@madman.nectar.cc> References: <200206262143.g5QLhiPS063301@freefall.freebsd.org> <86y9ctxipc.wl@daemon.musha.org> <86r8iepoal.wl@archon.local.idaemons.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <86r8iepoal.wl@archon.local.idaemons.org> User-Agent: Mutt/1.4i X-Url: http://www.nectar.cc/ Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Mon, Jul 08, 2002 at 06:22:10PM +0900, Akinori MUSHA wrote: > > I belive the compat{3x,2?} stuff (and probably compat4x too) in those > > branches also needs updating. In order to update the compat stuff, we > > must MFC the fix also to RELENG_{3,2_?} and then find out someone in > > our developers who can rebuild libc on the old systems. > > > > Security Officer/Team, would you give some consideration and organize > > the work? > > Ping? > > I don't believe we should ship 4.6.1-RELEASE and 5.0-DP2 with the hole > in compat libraries left untreated, but we should at least document it > in Release notes, sysinstall and ports/misc/compat*. I don't think anyone here has had time to look at this much. I believe have tested RELENG_3 patches ready-to-commit --- I'll make sure they are not held up beyond today. -- Jacques A. Vidrine http://www.nectar.cc/ NTT/Verio SME . FreeBSD UNIX . Heimdal Kerberos jvidrine@verio.net . nectar@FreeBSD.org . nectar@kth.se To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message