At 8:54 Uhr -0400 01.08.2002, Viktor Haag wrote:
>This may or may not affect the fink Openssh package; I don't have
>it installed, so I don't know from whence it pulls its sources.
>
>Apparently the codebase on ftp.openbsd.org has been trojaned. See
>the slashdot story posted Aug 01 at 0810 for more details.
>
>--

We do pull the sources from there, however, we are using the correct 
MD5 of the non-infected source base. Hence users would have to force 
a build if they want to build with the infected sources.

I guess we should change Fink to refuse to build if the MD5 doesn't 
match. Right now, it allows you to build anyway, on your own risk of 
course.


Cheers,

Max
-- 
-----------------------------------------------
Max Horn
Software Developer

email: <mailto:[EMAIL PROTECTED]>
phone: (+49) 6151-494890


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
Fink-users mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/fink-users

Reply via email to