Re: Remote execution in CUPS

2024-09-27 Thread Ian Darwin
On 9/27/24 11:05 AM, Kirill A. Korinsky wrote: On Fri, 27 Sep 2024 14:43:21 +0200, Chris Narkiewicz wrote: https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/ Is the cups in ports vulnerable as well? OpenBSD mises quite import pices of this attack: cups-browsed With

Re: Remote execution in CUPS

2024-09-27 Thread Kirill A . Korinsky
On Fri, 27 Sep 2024 17:19:47 +0200, Ian Darwin wrote: > > On 9/27/24 11:05 AM, Kirill A. Korinsky wrote: > > On Fri, 27 Sep 2024 14:43:21 +0200, > > Chris Narkiewicz wrote: > >> https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/ > >> > >> Is the cups in ports vulnerab

riscv64 bulk build report

2024-09-27 Thread jca
Bulk build on riscv64-1.ports.openbsd.org Started : Mon Sep 16 13:09:52 MDT 2024 Finished: Fri Sep 27 08:58:03 MDT 2024 Duration: 10 Days 19 hours 48 minutes Built using OpenBSD 7.6-beta (GENERIC.MP) #70: Sun Sep 15 16:54:55 MDT 2024 Built 10460 packages Number of packages built each day: Sep 1

Re: Remote execution in CUPS

2024-09-27 Thread Kirill A . Korinsky
On Fri, 27 Sep 2024 14:43:21 +0200, Chris Narkiewicz wrote: > > https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/ > > Is the cups in ports vulnerable as well? OpenBSD mises quite import pices of this attack: cups-browsed Without it, it isn't so dramatic. -- wbr, K

Remote execution in CUPS

2024-09-27 Thread Chris Narkiewicz
https://www.evilsocket.net/2024/09/26/Attacking-UNIX-systems-via-CUPS-Part-I/ Is the cups in ports vulnerable as well?

Re: roadmap for more privsep in pkgland

2024-09-27 Thread Marc Espie
On Sat, Sep 21, 2024 at 04:28:25AM -0600, Anthony J. Bentley wrote: > Marc Espie writes: > > Here's the basic pkg_add change, very lightly tested for now. > > Not that many lines, considering :) > > The manpage changes make sense to me. > > Typo: > > > + my $o = $class->new_owned_objet($args);

Re: roadmap for more privsep in pkgland

2024-09-27 Thread Marc Espie
On Fri, Aug 16, 2024 at 11:16:51AM +0100, Stuart Henderson wrote: > On 2024/08/15 18:33, Marc Espie wrote: > > Enter @extraglob > > > > > > basically: stuff like @extraglob /var/tomcat/conf/ > > will remove the tomcat dir with everything inside it > > > > or stuff like > > @extra