Follow @Openwall on Twitter for new release announcements and other news
[<prev] [<thread-prev] [day] [month] [year] [list]
Message-Id: <20250517131925.B156484E93@mail.netbsd.org>
Date: Sat, 17 May 2025 13:19:21 +0000
From: Taylor R Campbell <riastradh@...BSD.org>
To: oss-security@...ts.openwall.com
CC: oss-security@...ts.openwall.com, Eli Schwartz <eschwartz@...too.org>
Subject: Re: describing affected systems (was: screen: Multiple
	Security Issues in Screen (mostly affecting release 5.0.0 and setuid-root
	installations))

> Date: Fri, 16 May 2025 21:52:14 -0500
> From: Jacob Bachmeyer <jcb62281@...il.com>
> 
> On 5/16/25 13:07, Eli Schwartz wrote:
> > On 5/16/25 12:31 PM, Taylor R Campbell wrote:
> > [...]
> >> (a) the same pkgsrc packages are available on, e.g., NetBSD 9.x (which
> >>      is not EOL); and
> >>
> >> (b) pkgsrc is used on platforms other than NetBSD, including macOS,
> >>      SmartOS, and various Linux distributions (e.g., for unprivileged
> >>      use on HPC clusters where it is more flexible and up-to-date than
> >>      the Linux distribution's package manager).
> >>
> >> That is why it would be more accurate for the report to say
> >> `pkgsrc-2025Q1', not `NetBSD 10.1'.
> >
> > I strongly dispute this. It should instead list both, as both are
> > affected.
> 
> Would "systems using pkgsrc-2025Q1, notably including NetBSD 9.x and 
> NetBSD 10.1" have been a fair way of describing that set?

Sure, that's fine, or just `...notably including NetBSD' instead of
specifying versions since NetBSD and pkgsrc versions advance
independently.

If I gave anyone the impression that I'm trying to conceal its impact
on NetBSD users, as Eli has insinuated with fabricated quotes, I
apologize (for that and for all the off-topic noise this minor point
has generated) -- we did not escape this, and we are working to
address it for all pkgsrc users on NetBSD or otherwise.

This will be my last message on the subject in this thread; I'm sure
everyone is tired of hearing about it now.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.