tags 332432 - security
severity 332432 normal
retitle 332432 Remove vicf
thanks hon

Quoting Moritz Muehlenhoff <[EMAIL PROTECTED]> (2005-10-06 13:53:29 BST):
> Package: cfengine2
> Severity: important
> Tags: security
> 
> The security issues from recent DSA-836 are still unfixed in sid.

Have you seen the security fix? It's not important, really. No-one
uses the "vulnerable" script (vicf), and certainly not on an
automatic basis. It doesn't even run, so the security fix is in
effect a no-op.

# sh -x /usr/sbin/vicf
+ prefix=/usr
+ exec_prefix=/usr
+ sbindir=/usr/sbin
+ EDITOR=vi
+ [EMAIL PROTECTED]@
+ export EDITOR CFINPUTS
+ NOPARSE='cf.preconf|cfd.conf'
++ hostname
+ '[' wompom '!=' sentral ']'
+ echo /usr/sbin/vicf can only be run on host sentral.
/usr/sbin/vicf can only be run on host sentral.
+ exit 1

No, it isn't a conffile. It's just broken.

-- 
Andrew Stribblehill <[EMAIL PROTECTED]>
Senior Systems Programmer, IT Service, University of Durham, England


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to