Fw: [ale] Linux: Secure and Limits? - yet further off topic

Michael H. Warfield mhw at wittsend.com
Thu Nov 18 08:09:23 EST 1999


On Wed, Nov 17, 1999 at 11:05:38PM -0500, John Mills wrote:

> I looked at CERT and found a recommendation that wu-ftp-2.50 suffers the
> same buffer-overflow vulnerabilities as -2.4, and recommending upgrade to
> -2.6x. I can't find sources for this - in fact, wuarchive had -2.4. I got
> -2.50 from the redhat 'updates/6.0' directory at GIT, yesterday. Does

	Then somebody better check those archives, they're out of date.

> -2.6x exist, and is it buildable? CERT (or a link from CERT) noted that
> -2.6x is "slightly incompatible." What is exactly the state of things?

> What ftpd is a reasonable choice today?

	Here is what I got from ftp.wtfo.com (RedHat mirror):

	redhat/updates/6.0/i386/wu-ftpd-2.6.0-1.i386.rpm

> This is for RH6.0-i386, as you probably gather.

	Go to another mirror.  I use ftp.wtfo.com because I can use rsync
with them.

> TIA and Regards -
>  John Mills

	Mike
-- 
 Michael H. Warfield    |  (770) 985-6132   |  mhw at WittsEnd.com
  (The Mad Wizard)      |  (770) 331-2437   |  http://www.wittsend.com/mhw/
  NIC whois:  MHW9      |  An optimist believes we live in the best of all
 PGP Key: 0xDF1DD471    |  possible worlds.  A pessimist is sure of it!






More information about the Ale mailing list