Apache又来了安全公告。。。
刚刚想睡觉的时候收到了commit mail:
| |
共 294 篇文章。
刚刚想睡觉的时候收到了commit mail:
| |
| |
很想知道是怎么commit的……
To summarize the release engineering process: 4.10-RC3 has delayed again so 4.10-RELEASE won’t be released soon. Recently, RELENG_4_10 branch has received several critical bugfixes. I personally requested a MFC for a security vulnerablity related with timedc, and Tim has MFC’ed some other security related fixes. Matthew Dillon has submitted some VM patches (committed by Ken Smith) and they all get into RC3.
I have requested src/usr.sbin/timed/timedc/timedc.c, v 1.5 to be MFC’ed to RELENG_4 and RELENG_4_10 so it will get its way into the upcoming release. It has not decided whether this will be merged into RELENG_4_10 yet, however, it is very likely that this will.
Currently the settings are:
Strict RFC821 Envelop.
It seems that OpenBSD people has then patched cvs vulnerablity, though. In this version, OpenBSD has pf(4) improved a lot!
刚刚揭露的那个TCP漏洞OpenBSD在1999年就修正了……和FreeBSD现在用的方法类似,只是更严厉一些。折服了……
Yesterday someone has asked me about my diary system, I told her that my diary is managed by my own diary software, which is a close-source system (written in C#) and I do not want to share it with others because it is technically not a friendly one.
Mike Silberack has posted a patch related to illegal TCP RST attacks.
TCP is vulnerable?! Yes if your system relays on persist TCP connections, for example, routers supporting BGP. CERT has released a advisory about this.