lionux 写了:刚发现2010Q3没有nspluginwrapper的packages,2010Q2以前一直有的,netbsd的packages不太正常。
进入pkgsrc的/usr/pkgsrc/www/firefox-bin-flash里编译,也不行,系统提示:
代码: 全选
dhcppc1# make
=> Bootstrap dependency digest>=20010302: found digest-20080510
===> Checking for vulnerabilities in firefox-bin-flash-9.0.124
Package firefox-bin-flash-9.0.124 has a multiple-vulnerabilities vulnerability, see http://secunia.com/advisories/32163/
Package firefox-bin-flash-9.0.124 has a information-disclosure vulnerability, see http://www.adobe.com/support/security/bulletins/apsb08-18.html
Package firefox-bin-flash-9.0.124 has a remote-system-access vulnerability, see http://www.adobe.com/support/security/bulletins/apsb10-14.html
Package firefox-bin-flash-9.0.124 has a remote-system-access vulnerability, see http://www.adobe.com/support/security/bulletins/apsb10-14.html
Package firefox-bin-flash-9.0.124 has a remote-system-access vulnerability, see http://www.adobe.com/support/security/bulletins/apsb10-16.html
Package firefox-bin-flash-9.0.124 has a remote-system-access vulnerability, see http://www.adobe.com/support/security/bulletins/apsb10-16.html
Package firefox-bin-flash-9.0.124 has a arbitrary-code-execution vulnerability, see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2884
Package firefox-bin-flash-9.0.124 has a arbitrary-code-execution vulnerability, see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3654
ERROR: Define ALLOW_VULNERABLE_PACKAGES in mk.conf or IGNORE_URL in pkg_install.conf(5) if this package is absolutely essential.
*** Error code 1
看来安全问题不少,在两个服务器上(包括NetBSD自己的服务器)已经剔除了这个文件,其它的packages没有提供估计和这个有关系,也许是根据这个packages衍生出来的。