Re: [Spam] Fw: Merry Christmas from the FreeBSD Security Team

2011-12-23 Thread Daniel Staal
--As of December 23, 2011 5:45:42 PM +0100, Bas Smeelen is alleged to have 
said:



While I'm writing, a note to freebsd-update users:
FreeBSD-SA-11:07.chroot has a rather messy fix involving adding a new
interface to libc; this has the awkward side effect of causing the sizes
of some "symbols" (aka. functions) in libc to change, resulting in
cascading changes into many binaries.  The long list of updated files is
irritating, but isn't a sign that anything in freebsd-update went wrong.


--As for the rest, it is mine.

I appreciate the hard work, though I could wish it were better timed.  ;)

However, the above does worry me a bit: Is that same library change likely 
to affect ports?  Any way to tell which, if so?  (Or should I just start 
reinstalling everything...)


Daniel T. Staal

---
This email copyright the author.  Unless otherwise noted, you
are expressly allowed to retransmit, quote, or otherwise use
the contents for non-commercial purposes.  This copyright will
expire 5 years after the author's death, or in 30 years,
whichever is longer, unless such a period is in excess of
local copyright law.
---
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Fw: Merry Christmas from the FreeBSD Security Team

2011-12-23 Thread Bas Smeelen
_  
From: FreeBSD Security Officer [mailto:cperc...@freebsd.org]
To: freebsd-secur...@freebsd.org
Sent: Fri, 23 Dec 2011 16:41:20 +0100
Subject: Merry Christmas from the FreeBSD Security Team

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Hi all,

No, the Grinch didn't steal the FreeBSD security officer GPG key, and your eyes
aren't deceiving you: We really did just send out 5 security advisories.

The timing, to put it bluntly, sucks.  We normally aim to release advisories on
Wednesdays in order to maximize the number of system administrators who will be
at work already; and we try very hard to avoid issuing advisories any time close
to holidays for the same reason.  The start of the Christmas weekend -- in some
parts of the world it's already Saturday -- is absolutely not when we want to be
releasing security advisories.

Unfortunately my hand was forced: One of the issues (FreeBSD-SA-11:08.telnetd)
is a remote root vulnerability which is being actively exploited in the wild;
bugs really don't come any worse than this.  On the positive side, most people
have moved past telnet and on to SSH by now; but this is still not an issue we
could postpone until a more convenient time.

While I'm writing, a note to freebsd-update users: FreeBSD-SA-11:07.chroot has a
rather messy fix involving adding a new interface to libc; this has the awkward
side effect of causing the sizes of some "symbols" (aka. functions) in libc to
change, resulting in cascading changes into many binaries.  The long list of
updated files is irritating, but isn't a sign that anything in freebsd-update
went wrong.

- -- 
Colin Percival
Security Officer, FreeBSD | freebsd.org | The power to serve
Founder / author, Tarsnap | tarsnap.com | Online backups for the truly paranoid
-BEGIN PGP SIGNATURE-
Version: GnuPG v2.0.18 (FreeBSD)

iEYEARECAAYFAk70oR8ACgkQFdaIBMps37IHEwCeNT8dws04qyJ8yuOz7g2xd9Xs
IsoAn0QfaSE6i90zFBuk1k0isvrDMYO3
=p94J
-END PGP SIGNATURE-

merry Christmas

Disclaimer: http://www.ose.nl/email

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"