ftp.gnu.org got cracked... how does this affect FreeBSD?

Kris Kennaway kris at obsecurity.org
Wed Aug 13 13:58:12 PDT 2003


On Wed, Aug 13, 2003 at 10:50:41PM +0200, Martin wrote:
> 
> http://ftp.gnu.org/MISSING-FILES.README
> 
> They are still checking the archives and the available checksums.
> It seems that the sources have not been modified.
> 
> FreeBSD contains some GNU software. How is it handled when 
> foreign sources are imported?
> 
> I just want to know to sleep better this night... The ftp-server was
> cracked in March(!)... just imagine that. Lots of things can happen
> in such a long period of time.
> 
> Martin
> 
> PS.: Please post to the mailing list, I'm subscribed.

So far there's no evidence that any distfiles were compromised.  For
files in the ports collection, they would have been caught by the md5
checksum.

Kris

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-questions/attachments/20030813/8001b603/attachment.bin


More information about the freebsd-questions mailing list