summaryrefslogtreecommitdiffstats
path: root/usr.bin/last/last.c
diff options
context:
space:
mode:
authordelphij <delphij@FreeBSD.org>2015-08-19 18:32:36 +0000
committerdelphij <delphij@FreeBSD.org>2015-08-19 18:32:36 +0000
commit99883f69b1bd93a4794151ebf0a8d1eb98466375 (patch)
tree54d8ae5a2cd1f6105d5a65262f8ce3c84cf9aefe /usr.bin/last/last.c
parent0505b0e9eae628ba39e1880030f6113a2ddb54d9 (diff)
downloadFreeBSD-src-99883f69b1bd93a4794151ebf0a8d1eb98466375.zip
FreeBSD-src-99883f69b1bd93a4794151ebf0a8d1eb98466375.tar.gz
Instant-MFC r286933:
Issue warning and refuse to proceed further if the configured repository signature_type is unsupported by bootstrap pkg(7). Previously, when signature_type specified an unsupported method, the bootstrap pkg(7) would proceed like when signature_type is "none". MITM attackers may be able to use this vulnerability and bypass validation and install their own versions of pkg(8). At this time, only fingerprint and none are supported by the bootstrap pkg(7). FreeBSD's official pkg(8) repository uses the fingerprint method and is therefore unaffected. Errata candidate.
Diffstat (limited to 'usr.bin/last/last.c')
0 files changed, 0 insertions, 0 deletions
OpenPOWER on IntegriCloud