pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: CVS commit: pkgsrc/shells/bash



On Sep 26, 10:39am, obata%lins.jp@localhost ("OBATA Akio") wrote:
-- Subject: Re: CVS commit: pkgsrc/shells/bash

| Where this "new feature, change default behaviour" came from (in pkgsrc feature freeze)?

Me. This is a security fix. There are currently:

        - 2 CVE's
        - 1 official patch for one CVS
        - 1 unofficial one that fixes one regression by the official patch
        - a second regression POC

There is active discussion about adding prefixes and suffixes to
prevent parsing errors. I am definitely not going to wait for the
ultimate fix to come when there are active exploits in the wild
and unknown attack vectors. AKAMAI implemented something similar
(disabled the feature completely).

If you don't like it, bring it up with the pkgsrc gods. I am trying to
protect the innocent public the best way I can.

christos



Home | Main Index | Thread Index | Old Index