Re: FreeBSD Security Advisory FreeBSD-SA-09:16.rtld

2009-12-03 Thread Andrew Thompson
On Thu, Dec 03, 2009 at 08:06:40PM +0100, Timo Schoeler wrote: > On 12/03/2009 08:01 PM, Pieter de Boer wrote: > > Jamie Landeg Jones wrote: > >> > >> However, I'd still apply the patch in case some other way to exploit > >> the non-checking of the unsetenv return status crops up elsewhere. > >> >

Re: freebsd-update

2009-12-02 Thread Andrew Thompson
On Wed, Dec 02, 2009 at 08:13:45PM +0100, Eirik ?verby wrote: > On Dec 2, 2009, at 6:21 PM, Matthew Herzog wrote: > > > On 12/02/2009 09:11 AM, Alex Huth wrote: > >> Hello! > >> > >> Is it no longer possible to update minor 6.x releases to 6.3 or 6.4 with > >> the > >> script mentioned on the an

Re: should looking at an interface with 'ifconfig' trigger a ?change ?

2008-08-09 Thread Andrew Thompson
On Fri, Aug 08, 2008 at 03:18:36PM +0200, Oliver Fromme wrote: > Andrew Thompson wrote: > > Pete French wrote: > > > > The bce driver is not properly generating link state events. > > > > > > OK, that explains why it doesnt failover - but why does lo

Re: should looking at an interface with 'ifconfig' trigger a?change ?

2008-08-09 Thread Andrew Thompson
On Fri, Aug 08, 2008 at 04:00:56PM +0200, Marian Hettwer wrote: > Hi Oliver, > > On Fri, 8 Aug 2008 15:18:36 +0200 (CEST), Oliver Fromme > > > > Shouldn't that be considered a security flaw? After all, > > you can perform "ifconfig $IF" inside a jail to list the > > interface configuration, but

Re: Any ongoing effort to port /etc/rc.d/pf_boot, /etc/pf.boot.conf from NetBSD ?

2006-07-16 Thread Andrew Thompson
On Sun, Jul 16, 2006 at 11:17:14PM +0300, Ari Suutari wrote: > Hi, > > > Daniel Hartmeier wrote: > >You claimed there was a hole. If you can't explain what it consists of > >("thing X might get exposed prior to rc.d/pf due to the following > >sequence of events..."), > > > On FreeBSD 6.1,