Subject: package with security hole not flagged at build time
To: None <>
From: Steven M. Bellovin <>
List: pkgsrc-users
Date: 01/09/2007 10:38:34
According to audit-packages, fetchmail- has a security hole.
When I go to its directory and do a 'make', it builds it without
noticing the problem.  My pkgsrc is up-to-date (HEAD), as is my
audit-packages and the vulnerabilities file it uses.  (This is on
-current from about two weeks ago.)

		--Steve Bellovin,