OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: lynx - someone is deaf and blind ;)
From: Kris Kennaway (krisHUB.FREEBSD.ORG)
Date: Sun Mar 05 2000 - 00:09:06 CST


On Sun, 27 Feb 2000, Michal Zalewski wrote:

> extremely long URLs. I'm not going to give more examples here, as I'm
> afraid I might miss one or two that won't be fixed - developers, use your
> head, take a look at the code and fix every suspected piece of code, not
> only already published / described bugs.

I have just disabled the lynx port/package in FreeBSD. We won't be
shipping it in FreeBSD 4.0, or until this gets addressed. It's a shame
because it's such a popular and useful tool, but the risk to users is just
too great.

Thanks for notifying the world of these problems :)

Kris Kennaway

----
In God we Trust -- all others must submit an X.509 certificate.
    -- Charles Forsythe <forsythealum.mit.edu>