Re: openssldoesn't -overwrite-base again (was: FreeBSD-SA-08:05.openssh)



Dirk Meyer wrote:
The -overwrite-base option was only functional on FreeBSD 4.x
With FreeBSD 5.x the libs are spread in /lib and /usr/lib, so
even if the ports overwrite base libs, some tools still use the
old (unpatched) libs from /lib.

Couldn't this be addressed simply by removing the old libs,
possibly replacing with symlinks, in coordination with the
standard/base?

We shouldn't need to worry about base applications linked to the
old libs anyhow, unless a base app is making unreasonable
expectations. Better to fix those bugs in base, IMO, than have
multiple versions of key libraries.

Roger Marquis
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: "nanobsd" prototype
    ... But if we use something like or picobsd like crunch ... > The point of nanobsd is simply to create a tool for putting FreeBSD ... Is there a list of progs which get installed with libs etc? ... And have a script which lists all libs needed. ...
    (freebsd-current)
  • Re: linked ssl libraries to binary
    ... On freebsd 7 it uses the base ... libraries even when telling it to search in /usr/local. ... it might also happen if the base system and and ports ... is called) to make sure those libs override the 7.x libs. ...
    (freebsd-stable)
  • Re: cannot find -ldl
    ... > It's not needed on FreeBSD. ... The dlopen family of functions is in> libc. ... The configure script should probably have something like this> in it so it only uses libdl if it can't find dlopen with its current> set of libs:: ...
    (freebsd-questions)
  • Re: static binaries, jails and compat x
    ... | Now that we have dynamic binaries everywhere I'm discovering all those ... | freeBSD 4 jail to run a legacy app. ... have mixed i386/amd64 libs :-( I copy over the amd64 versions of ps etc. ... That way I can chroot in chroot without needing ...
    (freebsd-current)
  • Re: 5.x concerns
    ... > worked well in that and then they did the bind defaulting to base and ... > libs version jump, why wasnt this done in 5.0 ... should have been more feature and driver backports to FreeBSD 4, ...
    (freebsd-stable)