OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
FreeBSD Security Archives: Re: RSAREF updated patch (was Re: Se

Re: RSAREF updated patch (was Re: Security Advisory: Buffer overflow in RSAREF2 (fwd))


Subject: Re: RSAREF updated patch (was Re: Security Advisory: Buffer overflow in RSAREF2 (fwd))
From: Chris D. Faulhaber (jedgarfxp.org)
Date: Mon Dec 13 1999 - 12:21:08 CST


On Mon, 13 Dec 1999, Kris Kennaway wrote:

> Hmm, Satoshi? I did warn you I couldn't test the port :-)
>
> Kris
>
> On Mon, 13 Dec 1999, spork wrote:
>
> > I see it was committed this morning, but it appears to be broken:
> >
> > ftp> get rsaref.tar
> > local: rsaref.tar remote: rsaref.tar
> >
> > rootass[/usr/ports/security]# tar xvf rsaref.tar
> >
> > rootass[/usr/ports/security/rsaref]# date
> > Mon Dec 13 12:31:35 EST 1999
> > rootass[/usr/ports/security/rsaref]# make
> > ===> Extracting for rsaref-2.0
> > >> Checksum OK for rsaref20.1996.tar.Z.
> > ===> Patching for rsaref-2.0
> > ===> Applying FreeBSD patches for rsaref-2.0
> > 4 out of 4 hunks failed--saving rejects to rsa.c.rej
> > *** Error code 4
> >

The problem with the patch is whitespace. Attached is patch-ac with the
correct whitespace...tested to compile and work with openssl and openssh.

-----
Chris D. Faulhaber | You can ISO9001 certify the process of
System/Network Administrator, | shooting yourself in the foot, so long
Reality Check Information, Inc. | as the process is documented and reliably
<jedgarfxp.org> | produces the proper result.


To Unsubscribe: send mail to majordomoFreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



This archive was generated by hypermail 2b27 : Mon Dec 13 1999 - 12:23:18 CST