sysutils/cfs

Mikhail T. mi+thun at aldan.algebra.com
Mon Sep 5 17:15:51 UTC 2011


On -10.01.-28163 14:59, Chris Rees wrote:
>> I've had to deprecate sysutils/cfs -- there's a confirmed issue with
>> failing locks [1] which has been open for two years with no fix.
>>
> Whoops, also missed a CVE -- buffer overflows can cause a DoS.
> Expiration date altered to 1 month accordingly.

Is this the only vulnerability you are talking about?

    http://www.debian.org/security/2006/dsa-1138

Does not seem hard to fix at all... Listing all of the fatal problems 
would be helpful...

    -mi



More information about the freebsd-ports mailing list