Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 9 Mar 2009 11:50:34 +0200
From:      Ross Cameron <abalour@gmail.com>
To:        Zbigniew Szalbot <zszalbot@gmail.com>
Cc:        User Questions <freebsd-questions@freebsd.org>
Subject:   Re: roundcube security bug
Message-ID:  <35f70db10903090250q1b7c7dd9x30e1dc420fcfe0fc@mail.gmail.com>
In-Reply-To: <94136a2c0903090047j34ddb20t2bebb19e8353fc66@mail.gmail.com>
References:  <94136a2c0903090036q51d569dfk4a58ef0f8cceab05@mail.gmail.com> <49B4C89C.7080205@gmail.com> <94136a2c0903090047j34ddb20t2bebb19e8353fc66@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Mon, Mar 9, 2009 at 9:47 AM, Zbigniew Szalbot <zszalbot@gmail.com> wrote:

> On Mon, Mar 9, 2009 at 08:43, Brent Clark <brentgclarklist@gmail.com>
> wrote:
> > Hiya
> >
> > Have you notified and / or checked with the upstream authour (maybe the
> > mailinglist too)
>
> Not really. It requires subscribing to a mailing list which I don't
> have time to do at the moment.
>

Surely an attempted cracking attempt on you're server warrants making time?

Without detailed reports of issues like this how is the vendor expected to
correct the problem?
    Avoiding installing the code is just a lazy workaround, helping the
author's will improve the general open source software ecosystem.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?35f70db10903090250q1b7c7dd9x30e1dc420fcfe0fc>