[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: new suid-perl debian security update breaks qmail-scanner!



Turbo Fredriksson wrote:

Quoting Patrick Donker <list@webpagina.nu>:

I've made packages for my woody system(s):
/pub/debian/dists/woody-ol2.2/source/Qmail/qmail-scanner_1.22-8.diff.gz
/pub/debian/dists/woody-ol2.2/source/Qmail/qmail-scanner_1.22-8.dsc
/pub/debian/dists/woody-ol2.2/source/Qmail/qmail-scanner_1.22-8_i386.changes
/pub/debian/dists/woody-ol2.2/source/Qmail/qmail-scanner_1.22.orig.tar.gz

They have this fix. The problem is that SUID perl script should NOT
run '/usr/bin/suidperl' but only '/usr/bin/perl' (but be suid).

In my package, I fix this and a whole lot more. I see no reason why the
building of the 'binary' package shouldn't work on sarge...


Ok, where can I find these packages and do you also happen to have a
fixed 1.25? I could try and look at your packages to figure out how to
make the latest QS work.

Sorry, the URL is 'ftp://ftp.bayour.com/...'.

And I didn't even know that 1.25 existed. I've replaced QS with simscan.
It was just not possible to run QS site-wite on my UltraSPARC III/750Mhz
with 1Gb mem (go figure!! :).

With simscan, everything is dandy!

I was a bit quick sending 'thanks' :)
What I wanted to ask also is, do you recommend simscan over QS? I've read about it but dont know which is better....The box I am running my stuff on isnt very exciting either; P3 886 with 300something megs of ram. Yes I know, more mem should be put in, but that's something I had planned doing later...

-Patrick



Reply to: