Subject: Re: fixing 2003-017 on machines without compilers and source code
To: imtarget <fogdog@imtarget.cotse.net>
From: David Maxwell <david@crlf.net>
List: tech-security
Date: 10/11/2003 13:13:02
On Sat, Oct 11, 2003 at 12:39:39PM -0400, imtarget wrote:
> The advisory for 2003-017: OpenSSL multiple vulnerabilities only offers
> source-code solutions.
> 
> What is the fix method for devices without compilers and OS source code?

The releng server has built the netbsd-1-6 branch for most platforms
since the source tree was patched.

netbsd-1.6 binary sets are available here:

ftp://releng.netbsd.org/pub/NetBSD-daily/netbsd-1-6/200310060000/

You can use the upgrade option on the installation floppy, or you can
untar the sets manually. Be sure to either reboot, or restart all
affected processes afterwards.

-- 
David Maxwell, david@vex.net|david@maxwell.net -->
Net Musing #5: Redundancy in a network doesn't mean two of everything and
half the staff to run it.
					      - Tomas T. Peiser, CET