Est-ce que les problèmes mentionnés ci-bas ont été résolus (séparation de privilèges, correction des failles) ?
OpenBSD CVS log for ports/net/ethereal/Attic/distinfo:
Revision 1.20
Wed Jul 14 21:52:25 2004 UTC (5 years, 6 months ago) by pvalchev
Branches: MAIN
CVS tags: HEAD
FILE REMOVED
Changes since revision 1.19: +0 -0 lines
Remove ethereal from the ports tree. Right during 3.5, it had more than
a dozen remote holes being fixed, that we shipped with. Weeks later
things have not improved, and there continue to be problems reported
to bugtraq, and respective band-aids - but it is clear the ethereal
team does not care about security, as new protocols get added, and
nothing gets done about the many more holes that exist.
Maybe someone will at least privilege separate this one day, and then
the OpenBSD stance with respect to this may change.
Encouraging people to run broken software by distributing packages
with known security holes is not desired by any of us.
# sécurité...
Posté par Psychofox (Mastodon) . En réponse au journal WireShark la capture réseau. Évalué à 3.
OpenBSD CVS log for ports/net/ethereal/Attic/distinfo:
Revision 1.20
Wed Jul 14 21:52:25 2004 UTC (5 years, 6 months ago) by pvalchev
Branches: MAIN
CVS tags: HEAD
FILE REMOVED
Changes since revision 1.19: +0 -0 lines
Remove ethereal from the ports tree. Right during 3.5, it had more than
a dozen remote holes being fixed, that we shipped with. Weeks later
things have not improved, and there continue to be problems reported
to bugtraq, and respective band-aids - but it is clear the ethereal
team does not care about security, as new protocols get added, and
nothing gets done about the many more holes that exist.
Maybe someone will at least privilege separate this one day, and then
the OpenBSD stance with respect to this may change.
Encouraging people to run broken software by distributing packages
with known security holes is not desired by any of us.