From owner-freebsd-audit@FreeBSD.ORG Wed Sep 8 06:36:43 2004 Return-Path: Delivered-To: freebsd-audit@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1817716A4CE for ; Wed, 8 Sep 2004 06:36:43 +0000 (GMT) Received: from mail.broadpark.no (mail.broadpark.no [217.13.4.2]) by mx1.FreeBSD.org (Postfix) with ESMTP id CF0BA43D53 for ; Wed, 8 Sep 2004 06:36:42 +0000 (GMT) (envelope-from des@des.no) Received: from dwp.des.no (37.80-203-228.nextgentel.com [80.203.228.37]) by mail.broadpark.no (Postfix) with ESMTP id 4AC412AD1; Wed, 8 Sep 2004 08:37:18 +0200 (MEST) Received: by dwp.des.no (Postfix, from userid 2602) id 55009B85E; Wed, 8 Sep 2004 08:36:40 +0200 (CEST) To: kerochan ii References: <3b793f1a040907174043f4cad4@mail.gmail.com> From: des@des.no (=?iso-8859-1?q?Dag-Erling_Sm=F8rgrav?=) Date: Wed, 08 Sep 2004 08:36:40 +0200 In-Reply-To: <3b793f1a040907174043f4cad4@mail.gmail.com> (kerochan ii's message of "Tue, 7 Sep 2004 20:40:44 -0400") Message-ID: User-Agent: Gnus/5.1006 (Gnus v5.10.6) Emacs/21.3 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: quoted-printable cc: freebsd-audit@freebsd.org Subject: Re: portaudit false positive X-BeenThere: freebsd-audit@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: FreeBSD Security Audit List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 08 Sep 2004 06:36:43 -0000 kerochan ii writes: > portaudit started warning me about a vulnerability in the cvs server > in the base system. > It reports that the affected package is FreeBSD-502010. > I realised that this is actually a vulnerability fixed months ago, and > because i'm tracking RELENG_5_2 and thus running 5.2.1-p9, it was > fixed on my system before portaudit even reported vulnerabilities in > base. No. For various reasons, this vulnerability still hasn't been fixed in RELENG_5_2 or RELENG_4_10. DES --=20 Dag-Erling Sm=F8rgrav - des@des.no