DaemonForums  

Go Back   DaemonForums > DaemonForums.org > News

News News regarding BSD and related.

Reply
 
Thread Tools Display Modes
  #1   (View Single Post)  
Old 26th October 2018
shep shep is offline
Real Name: Scott
Rc.conf Instructor
 
Join Date: May 2008
Location: Dry and Dusty
Posts: 1,185
Default Xorg and OpenBSD security record on the Base Install.

Theo is not happy

https://marc.info/?l=openbsd-tech&m=154050351216908&w=2
Reply With Quote
  #2   (View Single Post)  
Old 26th October 2018
fvgit's Avatar
fvgit fvgit is offline
Tempvs fvgit
 
Join Date: May 2016
Location: perl -MMIME::Base64 -le 'print decode_base64("SGVyZSBiZSBkcmFnb25zC")'
Posts: 151
Default

Ouch. I wonder why that happened the way it did. Holding back sth. like that in the final run-up to a release seems weird.
Reply With Quote
  #3   (View Single Post)  
Old 27th October 2018
Carpetsmoker's Avatar
Carpetsmoker Carpetsmoker is offline
Real Name: Martin
Tcpdump Spy
 
Join Date: Apr 2008
Location: New Zealand
Posts: 2,201
Default

This is the patch that introduced the problem: https://gitlab.freedesktop.org/xorg/...mit/032b1d79b7

This is really silly mistake, lessons here are:

- Don't refactor code when doing a s/oldFunction/newFunction/; it's tempting, but also likely to introduce silly bugs like this.

- Code reviews are important!
__________________
UNIX was not designed to stop you from doing stupid things, because that would also stop you from doing clever things.

Last edited by Carpetsmoker; 29th October 2018 at 01:57 AM.
Reply With Quote
  #4   (View Single Post)  
Old 27th October 2018
fvgit's Avatar
fvgit fvgit is offline
Tempvs fvgit
 
Join Date: May 2016
Location: perl -MMIME::Base64 -le 'print decode_base64("SGVyZSBiZSBkcmFnb25zC")'
Posts: 151
Default

Carpetsmoker, your link is broken.

EDIT: found it:
https://gitlab.freedesktop.org/xorg/...mit/032b1d79b7

Courtesy of:
https://security.archlinux.org/CVE-2018-14665

Last edited by fvgit; 27th October 2018 at 08:49 AM.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
removing unused system daemons from the base install (for security) puffyborg OpenBSD Security 2 24th August 2018 08:15 PM
ftp.fr.openbsd.org not available by base ftp shep OpenBSD Installation and Upgrading 2 6th July 2015 04:38 PM
OpenBSD nginx will be removed from base in OpenBSD-5.7 jggimi News 2 27th August 2014 05:59 PM
xorg.conf doesn't exist & I want to keep record of my working Xorg setting daemonfowl OpenBSD General 14 28th August 2012 01:13 AM
How - To install GNOME vile I install OpenBSD ? looop OpenBSD Installation and Upgrading 6 24th April 2010 08:58 PM


All times are GMT. The time now is 09:57 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2018, Jelsoft Enterprises Ltd.
Content copyright © 2007-2010, the authors
Daemon image copyright ©1988, Marshall Kirk McKusick