Subject: Re: Security issue: irssi-0.8.4nb1.tgz
To: John Klos <john@sixgirls.org>
From: Lubomir Sedlacik <salo@Xtrmntr.org>
List: port-vax
Date: 06/05/2002 00:51:13
--LZvS9be/3tNcYl/X
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Tue, Jun 04, 2002 at 04:32:16PM -0400, John Klos wrote:
> As some of you may already know, irssi's source tarball was recently
> compromised and a backdoor was introduced. See:
> http://www.irssi.org/?page=3Dbackdoor
> http://online.securityfocus.com/news/462
> for more information.
>=20
> Although the 1.5.3 VAX binary packages were only uploaded in the last few
> days, there may be a chance that someone installed irssi from the binary
> package. If so, remove the package and compile it from source.
>=20
> The binary package has already been removed from the NetBSD server.

there is *nothing* wrong with the irssi binary package.  you should read
it once again more carefuly.  compilation from sources (e.g. pkgsrc) may
caused trouble (the backdoor was in configure script) and there is new
irssi package for some time available from pkgsrc.  please don't spread
such misinformation.

regards,

--=20
-- Lubomir Sedlacik <salo@Xtrmntr.org>   ASCII Ribbon campaign against  /"\=
 --
--                  <salo@silcnet.org>   e-mail in gratuitous HTML and  \ /=
 --
--                                       Microsoft proprietary formats   X =
 --
-- PGPkey: http://Xtrmntr.org/salo.pgp                                  / \=
 --
-- Key Fingerprint: DBEC 8BEC 9A90 ECEC 0FEF  716E 59CE B70B 7E3B 70E2     =
 --

--LZvS9be/3tNcYl/X
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (NetBSD)

iD8DBQE8/URhWc63C347cOIRAoJ7AKCm25DeHzdUKsx8Sd53j2CCJD+MBACfSPpd
yikmcko9loJqyTj3ZNxsgxo=
=EmM8
-----END PGP SIGNATURE-----

--LZvS9be/3tNcYl/X--