On Sat, Oct 22, 2016 at 8:32 PM, <[email protected]> wrote: > > ---------- Forwarded message ---------- > From: Nathaniel Reindl <[email protected]> > To: "Fossil SCM user's discussion" <[email protected]> > Cc: > Date: Sat, 22 Oct 2016 19:56:51 -0400 > Subject: Re: [fossil-users] OT: Why we should NEVER use inetd/xinetd > > On Oct 22, 2016, at 17:23, K. Fossil user <ticketpersonnal-fossil@yahoo. > fr> wrote: > > 2/ Xinetd is old (four years ?) so may be not secure. > > xinetd is actually older than that. It may have not, for whatever reason, > seen a recent release. >
I think what K meant was that it has been more than 4 years since the last new release of xinetd. I also noticed it was about 7 years to the previous release. I do agree that assuming too much from a project being long time since the latest release is folly. Even a very new release could be insecure. Xinetd is actually small and simple compared to a lot of servers with a lot of recent activity. It might be that none of the few currently open issues is an actual security problem. I have not audited the code, however, I don't see any recent CERT advisories about xinetd. I don't use xinetd. I have no need for it. I don't run any services other than Fossil on my computers.
_______________________________________________ fossil-users mailing list [email protected] http://lists.fossil-scm.org:8080/cgi-bin/mailman/listinfo/fossil-users

