[OpenAFS-devel] Re: [OpenAFS] Is OpenAFS vulnerable to CA-2003-10 ?

Derrick J Brashear shadow@dementia.org
Fri, 21 Mar 2003 11:49:35 -0500 (EST)


On Fri, 21 Mar 2003, Nathan Neulinger wrote:

> Once all of the other "trunk is completely useless for linux servers
> right now" problems are resolved, something I was thinking of working on
> (along with my 5 million other projects) is a cleanup of the XDR stuff.
> Disabling any non-used stuff would definately be an option here. (Does
> ANYONE use Rx directly for anything besides AFS?)

adm and emt. I've said it before.

Jim said:
> > Is xdr_mem.o used by anything?  It is only linked with the Windows version
> > of the code.  It makes me nervous to have known bad code in the tree, even
> > if it's unused.
> >
> > Let's either take it out of the tree, or patch it.

It should be patched before the 1.2.9 release, really.