I'm orphaning arc in Fedora Extras

Nicolas Mailhot nicolas.mailhot at laposte.net
Sat Oct 8 15:28:09 UTC 2005


Le samedi 08 octobre 2005 à 07:20 -0700, Howard Chu a écrit :
> Nicolas Mailhot wrote:
> > Hi,
> > 
> > I'm officially orphaning arc.
> 
> Sounds fine. I've always wondered why anybody still used it these days, 
> with its 11-character limit on filenames and such. I wrote the darn Unix 
> port and I stopped using it years ago.

All the damn legacy archiving formats must be maintained forever in
mail/file content scanners so they're not used as a malware enveloppe.
(But only the uncompress path is needed)

The problem is all the legacy archivers have often not been subjected to
a modern security audit, so they are a security risk themselves (both in
FOSS and commercial scanners, arc problems endanger amavis but some
commercial software was also subjected to an arj attack lately).

Regards,

-- 
Nicolas Mailhot
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 197 bytes
Desc: Ceci est une partie de message num?riquement sign?e
URL: <http://listman.redhat.com/archives/fedora-extras-list/attachments/20051008/db6959b9/attachment.sig>


More information about the fedora-extras-list mailing list