Re: portaudit question.....

From: Alex Zbyslaw (xfb52_at_dial.pipex.com)
Date: 09/29/05

  • Next message: Sasa Stupar: "RE: Problem with compiling sendmail+sasl (QUIT FBSD)"
    Date: Thu, 29 Sep 2005 10:55:41 +0100
    To: Wright Jim Contractor 14MDSS/SGSI <jim.wright.ctr@columbus.af.mil>
    
    

    Wright Jim Contractor 14MDSS/SGSI wrote:

    >I guess my question is this.
    >
    >How do I use the FreeBSD tools, Ports/Packages, etc, to install this latest
    >version??
    >
    >Or am I missing the concept altogether ?
    >
    >( I understand the process of downloading this latest version and installing
    >it manually. Just trying to understand and use the FreeBSD tools )
    >
    >
    >
    IMHO, the messages from portaudit are misleadingly worded. Portaudit is
    correct that some of the software you installed has *some kind* of
    security vulnerability. But everything else it says is potentially
    misleading.

    1) There may be no upgrade available yet. For there to be an upgrade
    the original code has to be fixed; in your example by the Mozilla team.
    Then, whoever is maintaining the port has to go through the work of
    fixing the new code to work on FreeBSD. For a few simple bug fixes,
    that may not be too hard, but it still has to be done. How long all this
    takes will vary from port to port. Mozilla is generally quite quick,
    from my experience, but xloadimage hung around for ages, not long ago.

    2) The advice that you should either upgrade or de-install in
    unnecessarily authoritarian and frightening. De-installing may not be
    an option, and the actual bug may have zero affect on your environment.
    And the presence of a bug does not indicate the presence of an exploit.
    If you are worried about a particular package then follow up the links
    portaudit provides and make up your mind what to do.

    However, that fact that you have so many packages reporting problems
    says that either you are doing something wrong or not checking often enough.

    1) cvsup your ports tree
    2) either make fetchindex in /usr/ports and run portsdb -u, or run
    portsdb -Uu (slower but more accurate)
    3) run pkg_version -L= to see what needs upgrading
    4) use portupgrade to upgrade on a schedule that suits. That might be
    daily or monthly depending on you environment. Remember to read
    /usr/port/UPDATING *before* doing any upgrades.

    All of that except the upgrading can be automated safely to run at 3am,
    or any other quiet time you might have.
    --Alex

    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"


  • Next message: Sasa Stupar: "RE: Problem with compiling sendmail+sasl (QUIT FBSD)"

    Relevant Pages

    • portmanager looping on libtool on 6.2 -> 6.3 upgrade
      ... I'm in the process of bringing a production web/mail server up to FreeBSD 7.0 from 6.2. ... After practicing the process on a non-production box set up in essentially the same manner, I discovered that the only major issue to look out for was the fact that I needed to hold back the upgrade of Python, since the CMS system running on the box will die if it doesn't have Python 2.4 specifically. ... Port Status Report "forced mode" ... I've tried simply going into /usr/ports/devel/libtool15 and running "suod make install clean", and I end up with this output: ...
      (freebsd-questions)
    • Are my Extensions installed properly?
      ... Attempting to install FrontPage extensions... ... Server extensions already installed on port 80. ... Starting upgrade, port: 80. ...
      (microsoft.public.frontpage.client)
    • Re: understanding this portupgrade error
      ... and it's failing on the net-snmp port. ... You may wish to ``make deinstall'' and install this port again ... by ``make reinstall'' to upgrade it properly. ...
      (freebsd-questions)
    • Snow Leopard advice for Ruby/Rails developers
      ... Here are some bumps I've had in the upgrade. ... reinstalled macports, and port wouldn't work at all before I did. ... installed binaries, the Snow Leopard install got confused and I ended ...
      (comp.lang.ruby)
    • Re: A portupgrade question
      ... portupgrade -a to upgrade a bunch of ports, ... should see that mysql-client is already installed and not try to install it ... the ldconfig_compat port which installs precisely one file: ...
      (freebsd-questions)