2001-04-23 19:46:58

by Dale Amon

[permalink] [raw]
Subject: Has the iptables security patch been vetted?

I'm sure you've run across this one:

http://netfilter.samba.org/security-fix/

I'd like to know how official this patch is, ie how
well checked out? I'd hardly want to cure one problem
and create another. And I'm uncomfortable with it at
first glance: I'd have to find figure out why it is
returning immediate success at that point, or rather
prove to myself that it is just skipping making the
bad table entries.

--
------------------------------------------------------
Use Linux: A computer Dale Amon, CEO/MD
is a terrible thing Village Networking Ltd
to waste. Belfast, Northern Ireland
------------------------------------------------------


2001-04-24 07:59:28

by Rusty Russell

[permalink] [raw]
Subject: Re: Has the iptables security patch been vetted?

In message <[email protected]> you write:
> I'm sure you've run across this one:
>
> http://netfilter.samba.org/security-fix/
>
> I'd like to know how official this patch is, ie how
> well checked out?

Hi Dale,

The preferred patch is available, and has been tested (several
new testsuite tests now exist) and submitted to Linus (et. al):

http://netfilter.filewatcher.org/security-fix/ftp-security2.patch
http://netfilter.samba.org/security-fix/ftp-security2.patch
http://netfilter.gnumonks.org/security-fix/ftp-security2.patch

Hope that helps,
Rusty.
--
Premature optmztion is rt of all evl. --DK