Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 04 Sep 1995 19:30:10 -0700
From:      Paul Traina <pst@shockwave.com>
To:        peter@haywire.dialix.com (Peter Wemm)
Cc:        freebsd-security@FreeBSD.org
Subject:   Re: syslog patches? 
Message-ID:  <199509050230.TAA00530@precipice.shockwave.com>
In-Reply-To: Your message of "04 Sep 1995 17:11:42 %2B0800." <42efse$fts$1@haywire.DIALix.COM> 

next in thread | previous in thread | raw e-mail | index | archive | help

  From: peter@haywire.dialix.com (Peter Wemm)
  Subject: Re: syslog patches?
  guido@spooky.lss.cp.philips.com (Guido van Rooij) writes:
  
  >After the intial posting of Paul Traina's modified syslog I haven't
  >seen a new attempt yet. I did see a NetBSD solution to the problem
  >though. My question: is theer any syslog.c that can be incorporated
  >in the source tree and to 2.1.0?
  
  >-Guido
  
  Not trying to offend Paul Traina, but I'd prefer to take Eric Allman's
  one and apply the necessary bandaids to it.

You won't offend me.
  
  But whatever the case, something *has* to go in, because if we ship
  2.1 with the buggy version, because of the identical binaries on each
  system, somebody *will* calculate the offsets and the code to subvert
  2.1R. 

Absolutely.
  
  If going with Paul Traina's version is what it takes to get it fixed,
  I'll gladly put aside my slight preference for Eric's version.

I don't care one way or another, however I would prefer the more paranoid
version in any case.  Eric's certainly had enough sendmail related bugs in
the past that I would actually prefer to go with a version that NOT everyone
is going to pound on.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199509050230.TAA00530>