Re: FreeBSD Security Advisory FreeBSD-SA-02:28.resolv

From: Robert Watson (rwatson@FreeBSD.ORG)
Date: 06/27/02


Date: Wed, 26 Jun 2002 21:21:10 -0400 (EDT)
From: Robert Watson <rwatson@FreeBSD.ORG>
To: Mark Hartley <mark@work.drapple.com>


On Wed, 26 Jun 2002, Mark Hartley wrote:

> I figured the reboot of the whole system I did (after going through the
> whole build and install of kernel & world), should have taken care of
> making sure any dynamically linked stuff is using the new & improved
> libc.
>
> So far I've only found a few apps that didn't get rebuilt that appear to
> be statically linked, and most of them are Kerberos tools (not sure why
> they weren't rebuilt with world), but I don't use Kerberos or run any
> Kerberos services. So far, it appears that a cvsup and rebuild of world
> is all that I'm going to need to do.

If you ended up with Kerberos installed somehow, it was probably an
accidental flip of a switch in sysinstall. I make a habit of walking
{/bin,/sbin,/usr/bin,/usr/sbin,/usr/libexec} after each installworld and
trimming old and unused binaries. Especially for things like UUCP in
-CURRENT, where the software presents some risk, and isn't going to get
automatically garbage collected by the install process. I'd go through
and check all the file modification dates in your binary directories and
trim things you know you don't need just to reduce the chances of
something slipping through the cracks. (Watch out not to delete old
symlinks -- unlike binaries, their timestamps aren't updated during the
install if they are still needed).

Robert N M Watson FreeBSD Core Team, TrustedBSD Projects
robert@fledge.watson.org Network Associates Laboratories

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: SSH 3.0.2 wont install
    ... I have gotten openssh 3.1 to install and working ... Able to SSH in as any user from anyhere. ... # Kerberos TGT Passing only works with the AFS kaserver ...
    (comp.security.ssh)
  • Rundll exception error involving shell32.dll and sysdm.cpl
    ... the OS is XP SP2 and current with all subsequent releases. ... I rebuilt it the second time using the XP ... As this was a problem from the start of a fresh install, ... The system logs do not report this error. ...
    (microsoft.public.windowsxp.general)
  • USB ports are not recognizing anything. controller not installed
    ... quantum bigfoot 10 gig hard drive as the primary hdd until ... back to the service that rebuilt it b4, ... he did not install the driver for the usb controller. ... since xp was installed i cant use anything, ...
    (microsoft.public.windowsxp.hardware)
  • Re: Postfix install on 4.9
    ... Looks like it cannot find a kerberos library. ... you did a mini or custom install you do not have it. ... > bunker# make install ... > Weitergabe des Inhaltes der Email nicht gestattet ist. ...
    (freebsd-stable)
  • Re: Removing /usr/lib32 on AMD64
    ... after an install; ... World is rebuilt but I haven't rebuilt my ports but they shouldn't have been built against the 32-bit libraries in the first place, ...
    (freebsd-stable)