Sophos and compat3x dependency

Kris Kennaway kris at obsecurity.org
Sat Apr 24 06:31:18 PDT 2004


On Sat, Apr 24, 2004 at 03:29:26PM +0200, Andy Wolf wrote:
> Hello,
> 
> currently I am trying to install Sophos Anti Virus and found out that 
> these binaries require FreeBSD 3.x compatibility. Now the misc/compat3x 
> port ist marked FORBIDDEN because of two security vulnerabilities 
> (FreeBSD-SA-03:08.realpath and FreeBSD-SA-03:05.xdr).
> 
> Any idea how to proceed ? Contacting Sophos ?

That would be a good idea.  Try explaining the problem to them and
asking them to produce a 4.x binary.

> Waiting for a fixed compat3x ?

I wouldn't hold my breath on that.  It's been over 4 months and no-one
in the community has expressed interest in fixing the security
vulnerabilities in question in the 3.x branch.

Kris
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-stable/attachments/20040424/1f09e1c2/attachment.bin


More information about the freebsd-stable mailing list