On Sat, Oct 22, 2016 at 8:32 PM, <[email protected]>
wrote:
>
> ---------- Forwarded message ----------
> From: Nathaniel Reindl <[email protected]>
> To: "Fossil SCM user's discussion" <[email protected]>
> Cc:
> Date: Sat, 22 Oct 2016 19:56:51 -0400
> Subject: Re: [fossil-users] OT: Why we should NEVER use inetd/xinetd
> > On Oct 22, 2016, at 17:23, K. Fossil user <ticketpersonnal-fossil@yahoo.
> fr> wrote:
> > 2/ Xinetd is old (four years ?) so may be not secure.
>
> xinetd is actually older than that. It may have not, for whatever reason,
> seen a recent release.
>

I think what K meant was that it has been more than 4 years since the last
new release of xinetd. I also noticed it was about 7 years to the previous
release.

I do agree that assuming too much from a project being long time since the
latest release is folly.

Even a very new release could be insecure.

Xinetd is actually small and simple compared to a lot of servers with a lot
of recent activity. It might be that none of the few currently open issues
is an actual security problem. I have not audited the code, however, I
don't see any recent CERT advisories about xinetd.

I don't use xinetd. I have no need for it. I don't run any services other
than Fossil on my computers.
_______________________________________________
fossil-users mailing list
[email protected]
http://lists.fossil-scm.org:8080/cgi-bin/mailman/listinfo/fossil-users

Reply via email to