PfSense 2.0-RC3 - Issues
-
Hi.
I was building the pfSense 2.0 RC3 and portaudit have show two security problems.develx86# portaudit -Fda
auditfile.tbz 100% of 68 kB 56 kBps
New database installed.
Database created: Mon Aug 8 15:25:00 UTC 2011
Affected package: php52-5.2.17_1
Type of problem: php – NULL byte poisoning.
Reference: http://portaudit.FreeBSD.org/3761df02-0f9c-11e0-becc-0022156e8794.htmlAffected package: syslog-ng-1.6.12_1
Type of problem: syslog-ng2 -- startup directory leakage in the chroot environment.
Reference: http://portaudit.FreeBSD.org/75f2382e-b586-11dd-95f9-00e0815b8da8.html2 problem(s) in your installed packages found.
The ports was updated. Have some way to move to a new version in this packages ?.
Thanks.
-
The PHP one doesn't matter - we aren't moving to 5.3 yet and there is no fix for that on 5.2.x.
The syslog one isn't really relevant to how it's used on pfSense so again, doesn't really matter.
If there is a problem, we usually address it with custom patches or updating as needed.