Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 15 May 2002 11:45:55 -0500
From:      "Jacques A. Vidrine" <nectar@FreeBSD.org>
To:        Brett Glass <brett@lariat.org>
Cc:        Makoto Matsushita <matusita@jp.FreeBSD.org>, security@FreeBSD.org
Subject:   Re: Patch/Announcement for DHCPD remote root hole?
Message-ID:  <20020515164555.GA33357@madman.nectar.cc>
In-Reply-To: <4.3.2.7.2.20020515101500.00e7fee0@nospam.lariat.org>
References:  <4.3.2.7.2.20020509175155.024efc00@nospam.lariat.org> <4.3.2.7.2.20020509175155.024efc00@nospam.lariat.org> <4.3.2.7.2.20020515101500.00e7fee0@nospam.lariat.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, May 15, 2002 at 10:37:49AM -0600, Brett Glass wrote:
> I think you misunderstood my message. Yes, the port is updated,
> but the package is not. In fact, if you use /stand/sysinstall
> to list the packages for 4.5-RELEASE on ftp.freebsd.org, you
> see an entry for isc-dhcp3-3.0.1.r4, which is quite old.
>
> This is a major security problem. Users who install FreeBSD 
> (either over the Net or from a CD-ROM) and use /stand/sysinstall 
> to bring in the package (which the program encourages them to do!), 
> will instantly make their systems vulnerable. Whenever a port is
> updated due to a security problem, the package on the FTP server
> and mirrors should be rebuilt at the same time. Otherwise, every
> new install -- even over the Net! -- is likely to be vulnerable.
> This is not good for users, for the Net, or for FreeBSD's
> reputation.

Careless system administrators / consultants are an even bigger
security problem.

If you install 4.5-RELEASE, you get packages that were generated for
4.5-RELEASE.  Surprise.

Updated packages are here:

ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-4.5-stable/All/
   isc-dhcp3-3.0.1.r8_1.tgz

This URL is listed as part of the Security Notice.

Cheers,
-- 
Jacques A. Vidrine <n@nectar.cc>                 http://www.nectar.cc/
NTT/Verio SME          .     FreeBSD UNIX     .       Heimdal Kerberos
jvidrine@verio.net     .  nectar@FreeBSD.org  .          nectar@kth.se

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020515164555.GA33357>