realpath(3) et al

Simon L. Nielsen simon at FreeBSD.org
Tue Aug 12 04:31:51 PDT 2003


On 2003.08.12 11:02:16 +0200, Devon H. O'Dell wrote:
> Is there a list of these bugs available anywhere? If not, what software is
> recommended to import, keep track of, and document these bugs?

The audit fixes from OpenBSD? I have no idea if they keep track of them
in some special way, but I think that integrating whem will require a
lot of looking at CVS commit logs and comparing code.

> Features such as a protected stack should, IMO, be implemented as soon as
> possible to keep FreeBSD heads-afloat right now in the security sense....
> OpenBSD has implemented this already and there are many patches for Linux to
> do the same... why don't we go ahead and shove some of this code into CVS?

This is a different issue which I don't think should be mixed with
general auditing, since it's far from a trivial change to support this
(at least so I heard - I haven't looked into it, and I have no plans to
do so).

-- 
Simon L. Nielsen
FreeBSD Documentation Team
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-security/attachments/20030812/8a9e02d3/attachment.bin


More information about the freebsd-security mailing list