Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 16 Jan 2001 05:38:48 -0800
From:      bmah@FreeBSD.org (Bruce A. Mah)
To:        Lars =?iso-8859-1?Q?K=F6ller?= <Lars.Koeller@uni-bielefeld.de>
Cc:        bmah@FreeBSD.org, FreeBSD-security@FreeBSD.org, FreeBSD-ports@FreeBSD.org
Subject:   Re: exmh security bugfix! 
Message-ID:  <200101161338.f0GDcmJ68936@bmah-freebsd-0.cisco.com>
In-Reply-To: <200101160704.IAA22365@hermes.hrz.uni-bielefeld.de> 
References:  <200101160704.IAA22365@hermes.hrz.uni-bielefeld.de>

next in thread | previous in thread | raw e-mail | index | archive | help
--==_Exmh_-394012406P
Content-Type: text/plain; charset=us-ascii

If memory serves me right, Lars =?iso-8859-1?Q?K=F6ller?= wrote:

> As the maintainer for exmh2 on the FreeBSD ports collection I would =
> inform you about an security issue just mentioned on BUGTRAQ (see =
> attached Mail).

Hi Lars--

Thanks for the note.  We (the exmh developers) have been working on a
fix; a new version (which will be called exmh-2.3) will be released
probably today.  I'll be updating the port as soon as this happens.  If
there isn't something put up by late today, I'll fix the port with a
patch from exmh's CVS repository.

More information is at:

http://www.beedub.com/exmh/symlink.html

<soapbox>
It would have been really nice if the person who originally reported
this bug to BUGTRAQ had bothered to contact *any* of the exmh developers
before posting to said list.  Apparently, nowadays, saying "I'M 3L33T
CUZ I F0UND A H0LE 1ST" is more important than giving developers a
chance to actually fix problems in their software.
</soapbox>

Cheers,

Bruce.

PS.  Yes, I should have put the patch into the port sooner.  I had
thought we would have cut a new exmh release earlier, which would have
made this a moot point.  One way or another FreeBSD will see the fix
today.



--==_Exmh_-394012406P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (FreeBSD)
Comment: Exmh version 2.2 06/23/2000

iD8DBQE6ZE7n2MoxcVugUsMRAuyLAKCkiZzqNA7M8b7fWJTRBN1m5V2wegCeINgC
o6z46C+fU41OtMSc8hh3cs0=
=yG0E
-----END PGP SIGNATURE-----

--==_Exmh_-394012406P--


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-ports" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200101161338.f0GDcmJ68936>