• # sécurité...

    Posté par (Mastodon) . En réponse au journal WireShark la capture réseau. Évalué à 3.

    Est-ce que les problèmes mentionnés ci-bas ont été résolus (séparation de privilèges, correction des failles) ?


    OpenBSD CVS log for ports/net/ethereal/Attic/distinfo:

    Revision 1.20
    Wed Jul 14 21:52:25 2004 UTC (5 years, 6 months ago) by pvalchev
    Branches: MAIN
    CVS tags: HEAD
    FILE REMOVED
    Changes since revision 1.19: +0 -0 lines

    Remove ethereal from the ports tree. Right during 3.5, it had more than
    a dozen remote holes being fixed, that we shipped with. Weeks later
    things have not improved, and there continue to be problems reported
    to bugtraq, and respective band-aids - but it is clear the ethereal
    team does not care about security, as new protocols get added, and
    nothing gets done about the many more holes that exist.

    Maybe someone will at least privilege separate this one day, and then
    the OpenBSD stance with respect to this may change.

    Encouraging people to run broken software by distributing packages
    with known security holes is not desired by any of us.