Re: [oss-security] describing affected systems

2025-05-18 Thread Eli Schwartz
On 5/16/25 10:52 PM, Jacob Bachmeyer wrote: > Am I mistaken that portage is unique to Gentoo, while pkgsrc is also > used for applications on systems other than its native NetBSD? Portage is also used by "Prefix", as I mentioned above, to run on any Linux system (e.g. for unprivileged use on HPC

Re: [oss-security] describing affected systems (was: screen: Multiple Security Issues in Screen (mostly affecting release 5.0.0 and setuid-root installations))

2025-05-17 Thread Taylor R Campbell
> Date: Fri, 16 May 2025 21:52:14 -0500 > From: Jacob Bachmeyer > > On 5/16/25 13:07, Eli Schwartz wrote: > > On 5/16/25 12:31 PM, Taylor R Campbell wrote: > > [...] > >> (a) the same pkgsrc packages are available on, e.g., NetBSD 9.x (which > >> is not EOL); and > >> > >> (b) pkgsrc is used

Re: [oss-security] describing affected systems (was: screen: Multiple Security Issues in Screen (mostly affecting release 5.0.0 and setuid-root installations))

2025-05-17 Thread Jan Schaumann
Jacob Bachmeyer wrote: > Would "systems using pkgsrc-2025Q1, notably including NetBSD 9.x and NetBSD > 10.1" have been a fair way of describing that set? I think that's a lot better, although I would probably have phrased it as: Systems using screen(1) built from pkgsrc, including binary packag

Re: [oss-security] describing affected systems (was: screen: Multiple Security Issues in Screen (mostly affecting release 5.0.0 and setuid-root installations))

2025-05-16 Thread Jacob Bachmeyer
On 5/16/25 13:07, Eli Schwartz wrote: On 5/16/25 12:31 PM, Taylor R Campbell wrote: [...] (a) the same pkgsrc packages are available on, e.g., NetBSD 9.x (which is not EOL); and (b) pkgsrc is used on platforms other than NetBSD, including macOS, SmartOS, and various Linux distribution