Re: Patch/Announcement for DHCPD remote root hole?

From: Rob Andrews (rob@cyberpunkz.org)
Date: 05/15/02


Date: Wed, 15 May 2002 12:03:24 -0500
From: Rob Andrews <rob@cyberpunkz.org>
To: Brett Glass <brett@lariat.org>



.- - - - - - Brett Glass wrote (2002/05/15 at 11:38:51 AM) - - - - - -
|
|> I think you misunderstood my message. Yes, the port is updated,
|> but the package is not. In fact, if you use /stand/sysinstall
|> to list the packages for 4.5-RELEASE on ftp.freebsd.org, you
|> see an entry for isc-dhcp3-3.0.1.r4, which is quite old.

Why is it that you complain about these same issues over and over
and get answers but seem to ignore them.. A user that installs
a fresh system should always take the time to update a system
to the current cvs branch with the latest updates for either -stable
or -release.

When you have a "release" version on CD you can't pull all those
cd's back in, make the changes and send them back out to the stores
now can you? Same logic applies to an ftp install of the released
version of FreeBSD. It is what was released and was known stable
at the time for the release. Updating that software before putting
it to use, since there is an availability to do so, is not only a
logical thing but its also common practice. (even Microsoft uses
windowsupdate for this purpose.. go figure..)

Packages imho should be avoided when possible. This is why we have
cvsup and the ports collection. If people take the time to read the
documentation as well as use countless other resources available
to them before or after installing the operating system then they
have a firm understanding of what needs to be done to take care of
their system and how to prevent troubles in the first place.
 
[ snip ]

Yes and those same packages are what they dump onto the cd's when
they release the cd sets to the general public. Read above. cvsup
and use ports.. same argument different week..

-r



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Relevant Pages

  • Re: portupgrade O(n^m)?
    ... wanted to try and port sections of portupgrade and its related tools to ... in 15 mn to 20 mn you have your packages. ... because packages don't break when compiling. ... pkg_add for around 500 ports replaced. ...
    (freebsd-hackers)
  • Re: portupgrade O(n^m)?
    ... in 15 mn to 20 mn you have your packages. ... >> because packages don't break when compiling. ... >> packages for installation are already present on the machine. ... >> modifying the origins of the ports. ...
    (freebsd-hackers)
  • Re: compiling ports with more than one job
    ... Let's call it width - e.g. the ability to compile packages at the ... to determine that just from the INDEX file and the installed ports. ... The way I would do it is have a single master process that works ... different logic would be needed for new installs. ...
    (freebsd-questions)
  • Re: [HOW-TO] cvsup for ports -- Re: compact portsnap db
    ... It is better to use all ports or all packages so either do: ... people install php at all. ... And yes there are some ports that don't have packages for licencing ... Preferring cvsup to portsnap is kinda like preferring vim ...
    (freebsd-questions)
  • Re: [HOW-TO] cvsup for ports -- Re: compact portsnap db
    ... The only problems I've ever seen with installing packages is that at ... And yes there are some ports that don't have packages for licencing etc ... though I can't recall ever having to install one of those. ... >> Preferring cvsup to portsnap is kinda like preferring vim over ...
    (freebsd-questions)

Loading