Re: FreeRadius Security hole

2002-02-19 Thread Steve Langasek
On Tue, Feb 19, 2002 at 02:19:26PM -0800, Scott Pell wrote: I am trying to load up the latest snapshot of FreeRadius, but I have been warned by FreeBSD developers to not run the released version because of the remotely exploitable buffer overflow security hole. Is there a patch that covers

Re: FreeRadius Security hole

2002-02-19 Thread Alan DeKok
Scott Pell [EMAIL PROTECTED] wrote: ... I just noticed something else: Trying update and install this port...getting the following: === freeradius-devel-20010310 is forbidden: Remotely exploitable buffer Does FreeBSD *really* include the March, 2001 version snapshot of the server?

Re: FreeRadius Security hole

2002-02-19 Thread Alan DeKok
Alan DeKok [EMAIL PROTECTED] wrote: Is there a patch that covers this? If so, we can get guys to take the security hold off of the port. If not, is there a timeframe to fix? It's fixed in the latest CVS snapshot. We haven't released another version yet. Sorry to follow up again...