Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 29 Apr 2025 09:35:06 +1000
From:      Greg 'groggy' Lehey <grog@freebsd.org>
To:        Dag-Erling =?iso-8859-1?Q?Sm=F8rgrav?= <des@freebsd.org>
Cc:        "freebsd-questions@FreeBSD.org" <freebsd-questions@freebsd.org>
Subject:   Re: Is FreeBSD insecure?
Message-ID:  <aBAQql62xkYTpucv@hydra.lemis.com>
In-Reply-To: <86msc0uwi3.fsf@ltc.des.dev>
References:  <MW4PR15MB5160CDBA9415E8712BD72842C9862@MW4PR15MB5160.namprd15.prod.outlook.com> <aA8n__R77NZsmR43@hydra.lemis.com> <86msc0uwi3.fsf@ltc.des.dev>

next in thread | previous in thread | raw e-mail | index | archive | help

--PJxIVGwT9Q/MfnMG
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Monday, 28 April 2025 at 17:38:28 +0200, Dag-Erling Sm=F8rgrav wrote:
> [op not cc:ed because they're obviously a troll]
>
> Greg 'groggy' Lehey <grog@freebsd.org> writes:
>> Security is an important issue nowadays, and no operating system is
>> perfect.  The FreeBSD project does everything possible to maintain its
>> good reputation, though so far I haven't seen anything that indicates
>> that the breach was the result of a FreeBSD bug.  Was it maybe a third
>> party application, or incorrect configuration?
>
> It was allegedly an RCE in a long-unsupported version of
> Ghostscript, so not FreeBSD's fault at all.

Yes, I've since heard that too.  See
https://www.theregister.com/2025/04/15/4chan_breached/, though it only
mentions out-of-date PHP and MySQL.  That would have happened with any
operating system.  But it's good to bring these details out into the
open.

Greg
--
When replying to this message, please copy the original recipients.
If you don't, I may ignore the reply or reply to the original recipients.
For more information, see http://www.lemis.com/questions.html
Sent from my desktop computer.
See complete headers for address and phone numbers.
This message is digitally signed.  If your Microsoft mail program
reports problems, please read http://lemis.com/broken-MUA.php

--PJxIVGwT9Q/MfnMG
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iF0EARECAB0WIQSaG4ICvM64RvkvCawi5vKQUHpCIwUCaBAQqgAKCRAi5vKQUHpC
I7n6AJ0Van9vx636WuxuW0O8a8A3sF6OCgCfWhwdHUp2NX8EHBSUb+5Mg24RHcE=
=Mxrg
-----END PGP SIGNATURE-----

--PJxIVGwT9Q/MfnMG--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?aBAQql62xkYTpucv>