compilation bug fix for bsds

Rick Moen rick at linuxmafia.com
Sun Jan 2 02:14:18 EST 2011


Quoting Yarin (yarin at warpmail.net):

> Not handling SIGPIPE is definitely a big deal, especially when that
> vulnerability lies in something that popular, (IMHO, SIGPIPE was a
> really bad design idea in the first place, but that's besides the
> point) but it looks like there's been a patch for that since 2003; so
> I would imagine that there aren't any djbdns versions with this
> problem in service any more.

Yarin --

Of the four maintained forks of djbdns, I've verified that Mark
Johnson's zinq-djbdns and Prasad J. Pandit's Red Hat djbdns implement
that patch.  I see no sign that it's in the other two (though I've 
not checked closely).  And, sadly, there are still many people running
unmodified 1.05.



More information about the list mailing list