Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

"Nuclear war can ruin your whole compile." -- Karl Lehenbauer


computers / alt.os.linux.mageia / Warning: Vpnc my overwrite your data

SubjectAuthor
o Warning: Vpnc my overwrite your dataMarkus Robert Kessler

1
Warning: Vpnc my overwrite your data

<uf4b1b$3p928$1@dont-email.me>

  copy mid

http://rslight.i2p/computers/article-flat.php?id=6647&group=alt.os.linux.mageia#6647

  copy link   Newsgroups: alt.os.linux.mageia
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: no_reply@dipl-ing-kessler.de (Markus Robert Kessler)
Newsgroups: alt.os.linux.mageia
Subject: Warning: Vpnc my overwrite your data
Date: Thu, 28 Sep 2023 16:53:00 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 50
Message-ID: <uf4b1b$3p928$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Thu, 28 Sep 2023 16:53:00 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="dd838107b1171c915e82b2b66025c065";
logging-data="3974216"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/cVn8ef0ymzPMwfGOSf1TD"
User-Agent: Pan/0.145 (Duplicitous mercenary valetism; d7e168a
git.gnome.org/pan2)
Cancel-Lock: sha1:8sac5dYR5ODMtRfzp/93T4DFUe4=
 by: Markus Robert Kessle - Thu, 28 Sep 2023 16:53 UTC

In addition to what had to be said in message
"Warning: Openconnect my overwrite your data"
I sadly have to report that the same is valid for vpnc.

I installed the most recent version from one of the official MGA9 sources
and a "sudo vpnc --pid-file /etc/shadow" overwrote this file (which I had
backuped before, expecting things like that).

In the times of MGA5 I realised that MGA's version of vpnc wasn't even
able to make a connection to AVM Fritzbox routers, and I wrote bug
reports and discussed this over and over. But always the same statement
of not having enough people, time etc.

At that time it was already clear that the source tarball was always the
same, but the other distros have their own patches to fix security issues
and not-working features like that. -- Same picture regarding openconnect.

So, I got a package from Suse linux and managed to port it to Mageia.

At that time, some MGA people convinced me of being a packager -- I was
willing to -- and I introduced this case to some "mentor". For privacy
reasons I won't write the name here. After a short while he had to tell
me, that my solution would mean multiple modifications per one svn
commit, and this was against Mageia's policies.

As there was no progress over weeks, I realized that it was pointless to
call myself a "mageia packager" and withdrew membership. Instead I
published this package along with several other packages on my homepage
for people who needed these features.

I tested my Suse port right this evening to be sure not to tell lies,
and, yes, the patches made by Suse are sanitizing user input, and hence,
this port behaves as desired. In contrast to the one from MGA9 repo.

To be honest, I am tired of writing bug reports that nobody cares about,
and so, I won't write one more against vpnc, and I won't do so regarding
openconnect.

Anyway, please keep in mind, that installing and running a Mageia
installation "out of the box" is risky, and, you should betatest
everything you use.

Best regards,

Markus

--
Please reply to group only.
For private email please use http://www.dipl-ing-kessler.de/email.htm

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor