Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 12 Jul 1996 21:13:47 -0700 (PDT)
From:      Doug White <dwhite@riley-net170-164.uoregon.edu>
To:        Annelise Anderson <andrsn@andrsn.stanford.edu>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: CERT FreeBSD ppp Advisory--Distribution?
Message-ID:  <Pine.BSF.3.91.960712210720.647G-100000@gdi.uoregon.edu>
In-Reply-To: <Pine.BSI.3.94.960711181650.22566A-100000@andrsn.stanford.edu>

next in thread | previous in thread | raw e-mail | index | archive | help
On Thu, 11 Jul 1996, Annelise Anderson wrote:

> CERT has distributed an advisory on a security problem with user ppp,
> information provided by FreeBSD, Inc.  Although I'm subscribed to the
> USENET group comp.security.announce (and it's there), I actually heard
> about it from my system administrator.

If anyone is interested, you can view the bulletin at the following URL:

ftp://info.cert.org/pub/cert_advisories/cert_bulletins/VB-96.11.freebsd

Basically take the suid bit off of ijppp until you patch it.  This 
requires the superuser to set up connections.  

> I would think such information ought to be available rather widely to
> people subscribed to various freebsd mailing lists, not just security,
> and should be on the freebsd home page as well.

The mailing list suggested would be the best stop for security information.


Doug White                              | University of Oregon  
Internet:  dwhite@resnet.uoregon.edu    | Residence Networking Assistant
http://gladstone.uoregon.edu/~dwhite    | Computer Science Major




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.91.960712210720.647G-100000>