Re: FreeBSD Security Advisory FreeBSD-SA-05:21.openssl

From: jere (jere_at_htnet.hr)
Date: 10/11/05

  • Next message: Vaida Bogdan: "Re: 5.X Tripwire Policy File"
    Date: Tue, 11 Oct 2005 15:32:57 +0200
    To: jimmy@inet-solutions.be
    
    

    unfortunately, this is the dark side of FreeBSD security patch
    management :) and I think also the main reason FreeBSD isn't so widely
    deployed into enterprise environments. It's ok for hacking or managing
    few boxes but try to imagine how to manage security on hundreds of them
    this way. :(

    on the other side (bright side :) you can try to use unofficial and
    often somewhat slowly updating solutions such as bsdupdate
    (www.bsdupdates.com) or freebsd-update (from ports tree).

    currently, FreeBSD just don't have a mechanism to handle security
    advisories in quick way.

    any suggestions/corrections ?

    j.

    jimmy@inet-solutions.be wrote:
    > Quoting FreeBSD Security Advisories <security-advisories@freebsd.org>:
    >
    >
    >>=============================================================================
    >>FreeBSD-SA-05:21.openssl Security Advisory
    >> The FreeBSD Project
    >
    > [..]
    >
    >>c) Recompile the operating system as described in
    >><URL:
    >>http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/makeworld.html >.
    >
    >
    > Is there any reason why one would need to compile the whole operating system?
    > I can understand that static linked apps need to be recompiled, but which
    > are there actually any at all (and linked against openssl)?
    >
    > Kind regards,
    > Jimmy Scott
    >
    > ----------------------------------------------------------------
    > This message has been sent through ihosting.be
    > To report spamming or other unaccepted behavior
    > by a iHosting customer, please send a message
    > to abuse@ihosting.be
    > ----------------------------------------------------------------
    > _______________________________________________
    > freebsd-security@freebsd.org mailing list
    > http://lists.freebsd.org/mailman/listinfo/freebsd-security
    > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    >
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Vaida Bogdan: "Re: 5.X Tripwire Policy File"

    Relevant Pages

    • RE: PAWS security vulnerability
      ... FreeBSD security list" isn't grammatically correct. ... "I told you to post the patch and info to the appropriate FreeBSD security ... "...This point and others are often discussed on the mailing lists, ...
      (freebsd-questions)
    • Changes to FreeBSD security support policy
      ... for tracking security fixes to FreeBSD 4.3-RELEASE: ... This eliminates support for the class of vulnerabilities exploitable ...
      (FreeBSD-Security)
    • RE: FreeBSD Security Survey
      ... Your also ignoring the fact that many security holes are a lot ... queries to this server to the NAS only. ... server with a new version of FreeBSD. ... Your survey responses lack any responses that indicate that leaving ...
      (freebsd-questions)
    • Re: Root exploit for FreeBSD
      ... poor security record. ... realize that FreeBSD has a grand total of 16 security problems for all ... The Uni is, of course, ...
      (freebsd-current)
    • Re: Root exploit for FreeBSD
      ... poor security record. ... realize that FreeBSD has a grand total of 16 security problems for all ... The Uni is, of course, ...
      (freebsd-questions)