Incorrect (?) documentation for setreuid(2) could lead to security issues for user code

2009-01-08 Thread Chris Palmer
According to section 6.4.1 of "Setuid Demystified": http://www.cs.ucdavis.edu/~hchen/paper/usenix02.html FreeBSD 4.4's setreuid(2) man page is wrong. The man page for FBSD 7 says the same thing. Is it still wrong, or was the implementation changed to match the documentation? This person noticed

Re: MD5 vs. SHA1 hashed passwords in /etc/master.passwd: can we configure SHA1 in /etc/login.conf?

2009-01-08 Thread O. Hartmann
Mike Tancsa wrote: > At 04:45 PM 1/3/2009, O. Hartmann wrote: > >> followed by a obligatory "cap_mkdb" seems to do something - changing >> root's password results in different hashes when selecting different >> hash algorithms like des, md5, sha1, blf or even sha256. >> >> Well, I never digged deep

Re: FreeBSD Security Advisory FreeBSD-SA-09:02.openssl

2009-01-08 Thread Brooks Davis
On Thu, Jan 08, 2009 at 08:53:17PM +0100, Zahemszky G?bor wrote: > Hi! > > Neither the lukemftpd, nor the openssl advisory speaks about > freebsd-update as an upgrade solution. (And I couldn't update with > it.) Why? I'm not sure what it wasn't mentioned, but it worked just fine for a dozen boxes

Re: FreeBSD Security Advisory FreeBSD-SA-09:02.openssl

2009-01-08 Thread Stanislav Sedov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Thu, 8 Jan 2009 20:53:17 +0100 Zahemszky Gábor mentioned: > Hi! > > Neither the lukemftpd, nor the openssl advisory speaks about > freebsd-update as an upgrade solution. (And I couldn't update with > it.) Why? > What is the problem with freebsd

Re: FreeBSD Security Advisory FreeBSD-SA-09:02.openssl

2009-01-08 Thread Zahemszky Gábor
> I'm not sure what it wasn't mentioned, but it worked just fine for a > dozen boxes at work. Opps, my fault. I tried to update one of my machines about 14 hours ago, but there weren't any updates. I tried it now, and it worked. Sorry for the noise. By, Gábor Zahemszky < Gabor at Zahemszky dot H

Re: FreeBSD Security Advisory FreeBSD-SA-09:02.openssl

2009-01-08 Thread Zahemszky Gábor
Hi! Neither the lukemftpd, nor the openssl advisory speaks about freebsd-update as an upgrade solution. (And I couldn't update with it.) Why? Bye, Gábor Zahemszky < Gabor at Zahemszky dot HU > -- #!/bin/ksh Z='21N16I25C25E30, 40M30E33E25T15U!'; IFS=' ABCDEFGHIJKLMNOPQRSTUVWXYZ '; set -- $Z;for