Subject: Re: NetBSD Security Advisory 2002-011: Sun RPC XDR decoder contains buffer overflow
To: John Darrow <John.P.Darrow@wheaton.edu>
From: Perry E. Metzger <perry@piermont.com>
List: tech-security
Date: 08/11/2002 21:30:17
John Darrow <John.P.Darrow@wheaton.edu> writes:
> Is there a reason that the same fix that was applied to the NetBSD-1.5
> and NetBSD-1.6 branches (namely, a pullup of revisions 1.13 and 1.14
> of lib/libc/rpc/xdr_array.c) can't be applied to the NetBSD-1.4 branch
> (other than "nobody's asked for it or tested it yet")?

I think 1.4 is likely about to be end of lifed -- certainly once 1.6
comes out (and 1.6 just hit release candidate). That said, maybe
Havard will decide to apply the patches.

However, ultimately that will come to an end. I know it would be nice
to support all back versions forever, but one can't reasonably do
that. Especially given how much the OS costs, upgrading every five
years does not seem like a lot to ask.

Perry