Re: FreeBSD Security Advisory FreeBSD-SA-05:01.telnet

From: Colin Percival (cperciva_at_freebsd.org)
Date: 03/28/05

  • Next message: Simon L. Nielsen: "Re: FreeBSD Security Advisory FreeBSD-SA-05:01.telnet"
    Date: Mon, 28 Mar 2005 13:39:29 -0800
    To: Will Yardley <freebsd-security@veggiechinese.net>
    
    

    Will Yardley wrote:
    >>b) Execute the following commands as root:
    >>
    >># cd /usr/src
    >># patch < /path/to/patch
    >
    > On my home machine (5.3-RELEASE) this failed - I had to go to
    > /usr/src/contrib/telnet/telnet for the patch to apply.

    Somehow the patch wasn't generated correctly for FreeBSD 5.x. It
    should be fixed soon; but what you've done works for now.

    >>c) Rebuild the operating system as described in
    >><URL:http://www.freebsd.org/doc/handbook/makeworld.html>.
    >
    > Just curious... why is it necessary to rebuild the whole operating
    > system? Normally, the security advisories just have you rebuild the
    > program in question - wouldn't that have sufficed here?

    For historical reasons, the telnet build is rather messy: Depending
    upon which options you have set in /etc/make.conf, telnet might need
    to be rebuilt from one of four different directories. We decided
    that having everybody run "make buildworld" was far less prone to
    error than trying to explain which particular version of telnet each
    system would need to have rebuilt.

    Colin Percival
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Simon L. Nielsen: "Re: FreeBSD Security Advisory FreeBSD-SA-05:01.telnet"

    Relevant Pages

    • Re: Exclusive binary files
      ... sys/sys/elf_common.h and rebuild). ... patch executables built on other FreeBSD systems. ...
      (freebsd-hackers)
    • Re: How Secure Is FBSD OTB?
      ... WRT the other BSDs you should say patch and rebuild only the affected ... binaries rather than then entire OS. ... It is the same for FreeBSD if you are careful about what you are doing. ...
      (comp.unix.bsd.freebsd.misc)
    • Re: FreeBSD Security Advisory FreeBSD-SA-05:01.telnet
      ... In general it's fine to bug the security team directly of stuff like ... the security advisories just have you rebuild the ... Due to multiple telnet versions (especially in FreeBSD 4) it was ...
      (FreeBSD-Security)
    • RE: FreeBSD Security Advisory FreeBSD-SA-05:01.telnet
      ... the security advisories just have you rebuild the ... > For historical reasons, the telnet build is rather messy: ... there isn't a cushy Makefile somewhere with a target to ...
      (FreeBSD-Security)
    • Uppercase usernames
      ... I have an HP-UX 11 system. ... upper-case usernames via telnet. ... I now need to rebuild a new system and can't remember how I did this. ...
      (comp.sys.hp.hpux)