All of lore.kernel.org
 help / color / mirror / Atom feed
From: Mike Westerhof <mike@mwester.net>
To: openembedded-devel@lists.openembedded.org
Subject: Re: samba-essential upgrade or remove?
Date: Mon, 15 Mar 2010 08:53:44 -0500	[thread overview]
Message-ID: <4B9E3BE8.1070800@mwester.net> (raw)
In-Reply-To: <201003150446.26284.holger+oe@freyther.de>

Holger Hans Peter Freyther wrote:
> On Monday 08 March 2010 13:51:35 Holger Hans Peter Freyther wrote:
>> On Monday 08 March 2010 13:42:07 Dr. Michael Lauer wrote:
>>> While I'm not using it atm., I recall that samba-essential was the only
>>> recipe that worked relatively painless when Matthias Hentges create it
>>> back then.
>> Then please fix it. You will do a great service to our users. The following
>> CVEs are not addressed:
>> 	CVE-2009-2813, CVE-2009-2948, CVE-2009-2906, CVE-2009-1888,
>> CVE-2008-4314, CVE-2008-1105, CVE-2007-6015, CVS-2007-4572,  CVE-2007-5398,
>> CVE-2007-2444, CVE-2007-2446, CVE-2007-2447, CVE-2007-0452, CVE-2007-0453,
>> CVE-2007-0454, CAN-2006-1059..
> 
> 
> any update? Is anyone volunteering to update samba-essential or shall we 
> remove it from the tree? I think we have a responsibility to our users that if 
> we install a network daemon that we at least fix the known security issues with 
> this one or remove it from our recipe collection... Opinions?
> 
> z.

Sigh.

I really don't think this recipe is worthy of this much controversy.
It's essential (hence the name) for certain very small NAS devices.

I fail to see how its presence is impacting others -- if you don't like
it, don't use it.  Simple.

Nevertheless, the same issues I face that prevent me from having the
time to figure out how to fix this recipe right now also preclude me
from spending time discussing and arguing my case on this.

If the presence of this recipe is so loathsome and offensive to the core
OE members that they would prefer to toss a distro out of OE, then go
ahead and do so.

As an alternative, I'll be happy to commit a change to that recipe that
renders it unbuildable for all but SlugOS -- that would ensure that no
one can build and install this "vulnerable" software in error, and
should suffice to address the issue.

-Mike (mwester)




  parent reply	other threads:[~2010-03-15 14:03 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-03-08 12:00 samba-essential upgrade or remove? Holger Hans Peter Freyther
2010-03-08 12:42 ` Dr. Michael Lauer
2010-03-08 12:51   ` Holger Hans Peter Freyther
2010-03-15  3:46     ` Holger Hans Peter Freyther
2010-03-15  7:30       ` Frans Meulenbroeks
2010-03-15  7:46         ` Holger Hans Peter Freyther
2010-03-15  8:08           ` Frans Meulenbroeks
2010-03-15  8:20             ` Martin Jansa
2010-03-15  9:13           ` Dr. Michael Lauer
2010-03-15  9:30           ` Koen Kooi
2010-03-15  9:51             ` Frans Meulenbroeks
2010-03-15 15:58               ` Holger Hans Peter Freyther
2010-03-15 18:20                 ` Frans Meulenbroeks
2010-03-16  0:50                   ` Holger Hans Peter Freyther
2010-03-15  9:56             ` Holger Hans Peter Freyther
2010-03-15  8:53       ` Koen Kooi
2010-03-15 13:46         ` Mike Westerhof
2010-03-15 13:53       ` Mike Westerhof [this message]
2010-03-15 14:20         ` Koen Kooi
2010-03-15 14:38         ` Holger Hans Peter Freyther
2010-03-15 14:58           ` Frans Meulenbroeks
2010-03-15 15:53             ` Holger Hans Peter Freyther

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4B9E3BE8.1070800@mwester.net \
    --to=mike@mwester.net \
    --cc=openembedded-devel@lists.openembedded.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.