<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-6621</id>
	<title>Nabble - freebsd-security-notifications</title>
	<updated>2009-10-02T13:12:05Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/freebsd-security-notifications-f6621.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/freebsd-security-notifications-f6621.html" />
	<subtitle type="html">Moderated Security Notifications [moderated, low volume]</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-25722001</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:14.devfs</title>
	<published>2009-10-02T13:12:05Z</published>
	<updated>2009-10-02T13:12:05Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:14.devfs &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Devfs / VFS NULL pointer race condition
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; kern
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-10-02
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Przemyslaw Frasunek
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FreeBSD 6.x and 7.x
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-05-18 10:41:59 UTC (RELENG_7, 7.2-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-10-02 18:09:56 UTC (RELENG_7_2, 7.2-RELEASE-p4)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-10-02 18:09:56 UTC (RELENG_7_1, 7.1-RELEASE-p8)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-10-02 18:09:56 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-10-02 18:09:56 UTC (RELENG_6_4, 6.4-RELEASE-p7)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-10-02 18:09:56 UTC (RELENG_6_3, 6.3-RELEASE-p13)
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;The device file system (devfs) provides access to system devices, such as
&lt;br&gt;storage devices and serial ports, via the file system namespace.
&lt;br&gt;&lt;br&gt;VFS is the Virtual File System, which abstracts file system operations in
&lt;br&gt;the kernel from the actual underlying file system.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;Due to the interaction between devfs and VFS, a race condition exists
&lt;br&gt;where the kernel might dereference a NULL pointer.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;Successful exploitation of the race condition can lead to local kernel
&lt;br&gt;privilege escalation, kernel data corruption and/or crash.
&lt;br&gt;&lt;br&gt;To exploit this vulnerability, an attacker must be able to run code with user
&lt;br&gt;privileges on the target system.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;An errata note, FreeBSD-EN-09:05.null has been released simultaneously to
&lt;br&gt;this advisory, and contains a kernel patch implementing a workaround for a
&lt;br&gt;more broad class of vulnerabilities. &amp;nbsp;However, prior to those changes, no
&lt;br&gt;workaround is available.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_2, RELENG_7_1, RELENG_6_4, or RELENG_6_3 security branch
&lt;br&gt;dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;7.1, and 7.2 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 6.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:14/devfs6.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:14/devfs6.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:14/devfs6.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:14/devfs6.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 7.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:14/devfs7.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:14/devfs7.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:14/devfs7.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:14/devfs7.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/sys/fs/devfs/devfs_vnops.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.114.2.17
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.40.2.11
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.18.2.13
&lt;br&gt;&amp;nbsp; src/sys/fs/devfs/devfs_vnops.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.114.2.16.2.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.18
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.17
&lt;br&gt;&amp;nbsp; src/sys/fs/devfs/devfs_vnops.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.114.2.15.2.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/sys/fs/devfs/devfs_vnops.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.149.2.9
&lt;br&gt;RELENG_7_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.23.2.7
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.11.2.8
&lt;br&gt;&amp;nbsp; src/sys/fs/devfs/devfs_vnops.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.149.2.8.2.2
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.507.2.13.2.11
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.9.2.12
&lt;br&gt;&amp;nbsp; src/sys/fs/devfs/devfs_vnops.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.149.2.4.2.2
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r197715
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r197715
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r197715
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r192301
&lt;br&gt;releng/7.2/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r197715
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r197715
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:14.devfs.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:14.devfs.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.10 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFKxltlFdaIBMps37IRAp4zAJwJEwIySGqxH4EXwc0wjkDXlcTb1wCfTltO
&lt;br&gt;Syds53GSM0YbsMNUVMGsLaU=
&lt;br&gt;=exPZ
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25722001&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25722001&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A14.devfs-tp25722001p25722001.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25721927</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:13.pipe</title>
	<published>2009-10-02T13:11:57Z</published>
	<updated>2009-10-02T13:11:57Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:13.pipe &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;kqueue pipe race conditions
&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; kern
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-10-02
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Przemyslaw Frasunek
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FreeBSD 6.x
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-10-02 18:09:56 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-10-02 18:09:56 UTC (RELENG_6_4, 6.4-RELEASE-p7)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-10-02 18:09:56 UTC (RELENG_6_3, 6.3-RELEASE-p13)
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;Pipes are a form of inter-process communication (IPC) provided by the
&lt;br&gt;FreeBSD kernel. &amp;nbsp;kqueue is an event management API that applications can
&lt;br&gt;use to monitor pipes and other kernel services.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;A race condition exists in the pipe close() code relating to kqueues,
&lt;br&gt;causing use-after-free for kernel memory, which may lead to an
&lt;br&gt;exploitable NULL pointer vulnerability in the kernel, kernel memory
&lt;br&gt;corruption, and other unpredictable results.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;Successful exploitation of the race condition can lead to local kernel
&lt;br&gt;privilege escalation, kernel data corruption and/or crash.
&lt;br&gt;&lt;br&gt;To exploit this vulnerability, an attacker must be able to run code on
&lt;br&gt;the target system.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;An errata notice, FreeBSD-EN-09:05.null has been released simultaneously to
&lt;br&gt;this advisory, and contains a kernel patch implementing a workaround for a
&lt;br&gt;more broad class of vulnerabilities. &amp;nbsp;However, prior to those changes, no
&lt;br&gt;workaround is available.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or to the RELENG_6_4, or
&lt;br&gt;RELENG_6_3 security branch dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3 and 6.4.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:13/pipe.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:13/pipe.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:13/pipe.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:13/pipe.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_event.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.93.2.7
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_fork.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.252.2.8
&lt;br&gt;&amp;nbsp; src/sys/kern/sys_pipe.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.184.2.6
&lt;br&gt;&amp;nbsp; src/sys/sys/event.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.32.2.1
&lt;br&gt;&amp;nbsp; src/sys/sys/pipe.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.29.2.1
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.40.2.11
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.18.2.13
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_event.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.93.2.6.6.2
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_fork.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.252.2.7.4.2
&lt;br&gt;&amp;nbsp; src/sys/kern/sys_pipe.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.184.2.4.2.3
&lt;br&gt;&amp;nbsp; src/sys/sys/event.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.32.12.2
&lt;br&gt;&amp;nbsp; src/sys/sys/pipe.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.29.16.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.18
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.17
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_event.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.93.2.6.4.1
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_fork.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.252.2.7.2.1
&lt;br&gt;&amp;nbsp; src/sys/kern/sys_pipe.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.184.2.2.6.3
&lt;br&gt;&amp;nbsp; src/sys/sys/event.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.32.10.1
&lt;br&gt;&amp;nbsp; src/sys/sys/pipe.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.29.12.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r197715
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r197715
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r197715
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://svn.freebsd.org/viewvc/base?view=revision&amp;revision=179243&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://svn.freebsd.org/viewvc/base?view=revision&amp;revision=179243&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:13.pipe.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:13.pipe.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.10 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFKxlthFdaIBMps37IRAlk2AJ9mUrNPd1RMztbzO4w7g+AxosqJzgCgmr5l
&lt;br&gt;FKxrbF0G4v9P6SyyfAdVOFY=
&lt;br&gt;=TWhC
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25721927&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25721927&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A13.pipe-tp25721927p25721927.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24710616</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:12.bind</title>
	<published>2009-07-28T17:48:35Z</published>
	<updated>2009-07-28T17:48:35Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:12.bind &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;BIND named(8) dynamic update message remote DoS
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; bind
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-07-29
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Matthias Urlichs
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-07-28 23:59:22 UTC (RELENG_7, 7.2-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-29 00:14:14 UTC (RELENG_7_2, 7.2-RELEASE-p3)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-29 00:14:14 UTC (RELENG_7_1, 7.1-RELEASE-p7)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-29 00:13:47 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-29 00:14:14 UTC (RELENG_6_4, 6.4-RELEASE-p6)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-29 00:14:14 UTC (RELENG_6_3, 6.3-RELEASE-p12)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2009-0696
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;NOTE: Due to this issue being accidentally disclosed early, updated
&lt;br&gt;binaries are yet not available via freebsd-update at the time this
&lt;br&gt;advisory is being published. &amp;nbsp;Email will be sent to the freebsd-security
&lt;br&gt;mailing list when the binaries are available via freebsd-update.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;BIND 9 is an implementation of the Domain Name System (DNS) protocols.
&lt;br&gt;The named(8) daemon is an Internet Domain Name Server.
&lt;br&gt;&lt;br&gt;Dynamic update messages may be used to update records in a master zone
&lt;br&gt;on a nameserver.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;When named(8) receives a specially crafted dynamic update message an
&lt;br&gt;internal assertion check is triggered which causes named(8) to exit.
&lt;br&gt;&lt;br&gt;To trigger the problem, the dynamic update message must contains a
&lt;br&gt;record of type &amp;quot;ANY&amp;quot; and at least one resource record set (RRset) for
&lt;br&gt;this fully qualified domain name (FQDN) must exist on the server.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;An attacker which can send DNS requests to a nameserver can cause it to
&lt;br&gt;exit, thus creating a Denial of Service situation.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No generally applicable workaround is available, but some firewalls
&lt;br&gt;may be able to prevent nsupdate DNS packets from reaching the
&lt;br&gt;nameserver.
&lt;br&gt;&lt;br&gt;NOTE WELL: Merely configuring named(8) to ignore dynamic updates is NOT
&lt;br&gt;sufficient to protect it from this vulnerability.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_2, RELENG_7_1, RELENG_6_4, or RELENG_6_3 security branch
&lt;br&gt;dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;7.1, and 7.2 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:12/bind.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:12/bind.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:12/bind.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:12/bind.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/lib/bind
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;# cd /usr/src/usr.sbin/named
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;# /etc/rc.d/named restart
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/update.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.5
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.40.2.10
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.18.2.12
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/update.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.3.2.1
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.17
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.16
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/update.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.2.2.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/update.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.3
&lt;br&gt;RELENG_7_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.23.2.6
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.11.2.7
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/update.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.2.2.1
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.507.2.13.2.10
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.9.2.11
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/update.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.1.4.1
&lt;br&gt;HEAD
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/update.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.4
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;head/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r195936
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r195934
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r195935
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r195935
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r195933
&lt;br&gt;releng/7.2/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r195935
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r195935
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;https://www.isc.org/node/474&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.isc.org/node/474&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0696&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0696&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:12.bind.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:12.bind.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFKb5koFdaIBMps37IRAglLAKCFGXI+MAsksnK5TZB/8L3UFhPS1gCgl7q5
&lt;br&gt;6fCpOeBcf7f83dVfKRDVF0I=
&lt;br&gt;=akJW
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=24710616&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=24710616&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A12.bind-tp24710616p24710616.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23960052</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:09.pipe</title>
	<published>2009-06-10T03:41:55Z</published>
	<updated>2009-06-10T03:41:55Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:09.pipe &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local information disclosure via direct pipe writes
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; kern
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-06-10
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Pieter de Boer
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-06-10 10:31:11 UTC (RELENG_7, 7.2-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_7_2, 7.2-RELEASE-p1)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_7_1, 7.1-RELEASE-p6)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_6_4, 6.4-RELEASE-p5)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_6_3, 6.3-RELEASE-p11)
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;One of the most commonly used forms of interprocess communication on
&lt;br&gt;FreeBSD and other UNIX-like systems is the (anonymous) pipe. &amp;nbsp;In this
&lt;br&gt;mechanism, a pair of file descriptors is created, and data written to
&lt;br&gt;one descriptor can be read from the other.
&lt;br&gt;&lt;br&gt;FreeBSD's pipe implementation contains an optimization known as &amp;quot;direct
&lt;br&gt;writes&amp;quot;. &amp;nbsp;In this optimization, rather than copying data into kernel
&lt;br&gt;memory when the write(2) system call is invoked and then copying the
&lt;br&gt;data again when the read(2) system call is invoked, the FreeBSD kernel
&lt;br&gt;takes advantage of virtual memory mapping to allow the data to be copied
&lt;br&gt;directly between processes.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;An integer overflow in computing the set of pages containing data to be
&lt;br&gt;copied can result in virtual-to-physical address lookups not being
&lt;br&gt;performed.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;An unprivileged process can read pages of memory which belong to other
&lt;br&gt;processes or to the kernel. &amp;nbsp;These may contain information which is
&lt;br&gt;sensitive in itself; or may contain passwords or cryptographic keys
&lt;br&gt;which can be indirectly exploited to gain sensitive information or
&lt;br&gt;access.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but systems without untrusted local users
&lt;br&gt;are not vulnerable. &amp;nbsp;System administrators are reminded that even if a
&lt;br&gt;system is not intended to have untrusted local users, it may be possible
&lt;br&gt;for an attacker to exploit some other vulnerability to obtain local user
&lt;br&gt;access to a system.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_2, RELENG_7_1, RELENG_6_4, or RELENG_6_3 security branch
&lt;br&gt;dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;7.1, and 7.2 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:09/pipe.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:09/pipe.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:09/pipe.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:09/pipe.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/sys/kern/sys_pipe.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.184.2.5
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.40.2.9
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.18.2.11
&lt;br&gt;&amp;nbsp; src/sys/kern/sys_pipe.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.184.2.4.2.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.16
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.15
&lt;br&gt;&amp;nbsp; src/sys/kern/sys_pipe.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.184.2.2.6.2
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/sys/kern/sys_pipe.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.191.2.5
&lt;br&gt;RELENG_7_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.23.2.4
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.11.2.5
&lt;br&gt;&amp;nbsp; src/sys/kern/sys_pipe.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.191.2.3.4.2
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.9
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.9.2.10
&lt;br&gt;&amp;nbsp; src/sys/kern/sys_pipe.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.191.2.3.2.2
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;releng/7.2/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:09.pipe.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:09.pipe.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkovjN0ACgkQFdaIBMps37JkXwCgmLcEMOMAEIXRoJ220zwZhMKn
&lt;br&gt;f+gAn1bZyLMhfZU7TI0xxhizwetDwMVI
&lt;br&gt;=J37B
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23960052&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23960052&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A09.pipe-tp23960052p23960052.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23959822</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:10.ipv6</title>
	<published>2009-06-10T03:41:49Z</published>
	<updated>2009-06-10T03:41:49Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:10.ipv6 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Missing permission check on SIOCSIFINFO_IN6 ioctl
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netinet6
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-06-10
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Hiroki Sato
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-06-10 10:31:11 UTC (RELENG_7, 7.2-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_7_2, 7.2-RELEASE-p1)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_7_1, 7.1-RELEASE-p6)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_6_4, 6.4-RELEASE-p5)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_6_3, 6.3-RELEASE-p11)
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;IPv6 is a new Internet Protocol, designed to replace (and avoid many of
&lt;br&gt;the problems with) the current Internet Protocol (version 4). &amp;nbsp;Many
&lt;br&gt;properties of the FreeBSD IPv6 network stack can be configured via the
&lt;br&gt;ioctl(2) interface.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;The SIOCSIFINFO_IN6 ioctl is missing a necessary permissions check.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;Local users, including non-root users and users inside jails, can set
&lt;br&gt;some IPv6 interface properties. &amp;nbsp;These include changing the link MTU
&lt;br&gt;and disabling interfaces entirely. &amp;nbsp;Note that this affects IPv6 only;
&lt;br&gt;IPv4 functionality cannot be affected by exploiting this vulnerability.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but systems without local untrusted users
&lt;br&gt;are not vulnerable.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_2, RELENG_7_1, RELENG_6_4, or RELENG_6_3 security branch
&lt;br&gt;dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;7.1, and 7.2 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 6.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:10/ipv6-6.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:10/ipv6-6.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:10/ipv6-6.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:10/ipv6-6.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 7.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:10/ipv6.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:10/ipv6.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:10/ipv6.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:10/ipv6.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.51.2.13
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.40.2.9
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.18.2.11
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.51.2.12.2.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.16
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.15
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.51.2.11.2.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.73.2.7
&lt;br&gt;RELENG_7_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.23.2.4
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.11.2.5
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.73.2.6.2.2
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.9
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.9.2.10
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.73.2.4.2.2
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;releng/7.2/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:10.ipv6.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:10.ipv6.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkovjOUACgkQFdaIBMps37IFxwCgj0o1r4IQMIEvp3y4oIqhQwxe
&lt;br&gt;cI8AoIlxweqjakKxu/A/Z4+xjoGmqUdF
&lt;br&gt;=/kNi
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23959822&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23959822&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A10.ipv6-tp23959822p23959822.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23959905</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:11.ntpd</title>
	<published>2009-06-10T03:41:45Z</published>
	<updated>2009-06-10T03:41:45Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:11.ntpd &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ntpd stack-based buffer-overflow vulnerability
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ntpd
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-06-10
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Chris Ries
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-06-10 10:31:11 UTC (RELENG_7, 7.2-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_7_2, 7.2-RELEASE-p1)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_7_1, 7.1-RELEASE-p6)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_6_4, 6.4-RELEASE-p5)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-10 10:31:11 UTC (RELENG_6_3, 6.3-RELEASE-p11)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2009-1252
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;The ntpd(8) daemon is an implementation of the Network Time Protocol (NTP)
&lt;br&gt;used to synchronize the time of a computer system to a reference time
&lt;br&gt;source.
&lt;br&gt;&lt;br&gt;Autokey is a security model for authenticating Network Time Protocol
&lt;br&gt;(NTP) servers to clients, using public key cryptography.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;The ntpd(8) daemon is prone to a stack-based buffer-overflow when it is
&lt;br&gt;configured to use the 'autokey' security model.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;This issue could be exploited to execute arbitrary code in the context of
&lt;br&gt;the service daemon, or crash the service daemon, causing denial-of-service
&lt;br&gt;conditions.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;Use IP based restrictions in ntpd(8) itself or in IP firewalls to
&lt;br&gt;restrict which systems can send NTP packets to ntpd(8).
&lt;br&gt;&lt;br&gt;Note that systems will only be affected if they have the &amp;quot;autokey&amp;quot; option
&lt;br&gt;set in /etc/ntp.conf; FreeBSD does not ship with a default ntp.conf file,
&lt;br&gt;so will not be affected unless this option has been explicitly enabled by
&lt;br&gt;the system administrator.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_2, RELENG_7_1, RELENG_6_4, or RELENG_6_3 security branch
&lt;br&gt;dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;7.1, and 7.2 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 6.3]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:11/ntpd63.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:11/ntpd63.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:11/ntpd63.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:11/ntpd63.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 6.4 and 7.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:11/ntpd.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:11/ntpd.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:11/ntpd.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:11/ntpd.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/usr.sbin/ntp/ntpd
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;# /etc/rc.d/ntpd restart
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/contrib/ntp/ntpd/ntp_crypto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.8.3
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.40.2.9
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.18.2.11
&lt;br&gt;&amp;nbsp; src/contrib/ntp/ntpd/ntp_crypto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.8.1.2.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.16
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.15
&lt;br&gt;&amp;nbsp; src/contrib/ntp/ntpd/ntp_crypto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.20.2
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/contrib/ntp/ntpd/ntp_crypto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.18.3
&lt;br&gt;RELENG_7_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.23.2.4
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.11.2.5
&lt;br&gt;&amp;nbsp; src/contrib/ntp/ntpd/ntp_crypto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.18.2.2.1
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.9
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.9.2.10
&lt;br&gt;&amp;nbsp; src/contrib/ntp/ntpd/ntp_crypto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.18.1.2.2
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;releng/7.2/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r193893
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:11.ntpd.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:11.ntpd.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkovjOwACgkQFdaIBMps37KRpwCfaQF9q8KhElv6LqgFv3DX2h9c
&lt;br&gt;hbEAn2Q0X8Qv8r5OySnhlAw2pMxlxkXK
&lt;br&gt;=Mh2u
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23959905&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23959905&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A11.ntpd-tp23959905p23959905.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23342517</id>
	<title>FreeBSD supported branches update</title>
	<published>2009-05-01T19:22:48Z</published>
	<updated>2009-05-01T19:22:48Z</updated>
	<author>
		<name>FreeBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;Hello Everyone,
&lt;br&gt;&lt;br&gt;The branches supported by the FreeBSD Security Officer have been updated
&lt;br&gt;to reflect the EoL (end-of-life) of FreeBSD 7.0. &amp;nbsp;The new list is below
&lt;br&gt;and at &amp;lt;URL: &lt;a href=&quot;http://security.freebsd.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.freebsd.org/&lt;/a&gt;&amp;nbsp;&amp;gt;. &amp;nbsp;Please note that FreeBSD
&lt;br&gt;7.0 was originally announced with an EoL date of February 28, 2009, but
&lt;br&gt;the EoL was delayed by two months in order to allow a 3 month window for
&lt;br&gt;systems to be upgraded to FreeBSD 7.1.
&lt;br&gt;&lt;br&gt;Users of FreeBSD 7.0 are advised to upgrade promptly to FreeBSD 7.1,
&lt;br&gt;either by downloading an updated source tree and building updates manually,
&lt;br&gt;or (for i386 and amd64 systems) using the FreeBSD Update utility as
&lt;br&gt;described in the FreeBSD 7.1 release announcement. &amp;nbsp;Some users may wish to
&lt;br&gt;wait for the upcoming FreeBSD 7.2-RELEASE; however, they should be aware
&lt;br&gt;that FreeBSD 7.2-RELEASE will only receive &amp;quot;normal&amp;quot; support (i.e., support
&lt;br&gt;for 12 months) and consequently it will not be supported for as long as
&lt;br&gt;FreeBSD 7.1.
&lt;br&gt;&lt;br&gt;[Excerpt from &lt;a href=&quot;http://security.freebsd.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.freebsd.org/&lt;/a&gt;&amp;nbsp;follows]
&lt;br&gt;&lt;br&gt;FreeBSD Security Advisories
&lt;br&gt;&lt;br&gt;~ &amp;nbsp; The FreeBSD Security Officer provides security advisories for
&lt;br&gt;~ &amp;nbsp; several branches of FreeBSD development. These are the -STABLE
&lt;br&gt;~ &amp;nbsp; Branches and the Security Branches. (Advisories are not issued for
&lt;br&gt;~ &amp;nbsp; the -CURRENT Branch.)
&lt;br&gt;&lt;br&gt;~ &amp;nbsp; &amp;nbsp; * The -STABLE branch tags have names like RELENG_7. The
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; corresponding builds have names like FreeBSD 7.0-STABLE.
&lt;br&gt;&lt;br&gt;~ &amp;nbsp; &amp;nbsp; * Each FreeBSD Release has an associated Security Branch. The
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Branch tags have names like RELENG_7_0. The
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; corresponding builds have names like FreeBSD 7.0-RELEASE-p1.
&lt;br&gt;&lt;br&gt;~ &amp;nbsp; Isses affecting the FreeBSD Ports Collection are covered in the
&lt;br&gt;~ &amp;nbsp; FreeBSD VuXML document.
&lt;br&gt;&lt;br&gt;~ &amp;nbsp; Each branch is supported by the Security Officer for a limited
&lt;br&gt;~ &amp;nbsp; time only, and is designated as one of `Early adopter', `Normal',
&lt;br&gt;~ &amp;nbsp; or `Extended'. &amp;nbsp;The designation is used as a guideline for
&lt;br&gt;~ &amp;nbsp; determining the lifetime of the branch as follows.
&lt;br&gt;&lt;br&gt;~ &amp;nbsp; Early adopter
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; Releases which are published from the -CURRENT branch will be
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; supported by the Security Officer for a minimum of 6 months
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; after the release.
&lt;br&gt;&lt;br&gt;~ &amp;nbsp; Normal
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; Releases which are published from a -STABLE branch will be
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; supported by the Security Officer for a minimum of 12 months
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; after the release, and for sufficient additional time (if
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; needed) to ensure that there is a newer release for at least
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; 3 months before the older Normal release expires.
&lt;br&gt;&lt;br&gt;~ &amp;nbsp; Extended
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; Selected releases (normally every second release plus the last
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; release from each -STABLE branch) will be supported by the
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Officer for a minimum of 24 months after the release,
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; and for sufficient additional time (if needed) to ensure that
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; there is a newer Extended release for at least 3 months before
&lt;br&gt;~ &amp;nbsp; &amp;nbsp; &amp;nbsp; the older Extended release expires.
&lt;br&gt;&lt;br&gt;~ &amp;nbsp; The current designation and estimated lifetimes of the currently
&lt;br&gt;~ &amp;nbsp; supported branches are given below. &amp;nbsp;The Estimated EoL (end-of-life)
&lt;br&gt;~ &amp;nbsp; column gives the earliest date on which that branch is likely to be
&lt;br&gt;~ &amp;nbsp; dropped. &amp;nbsp;Please note that these dates may be extended into the
&lt;br&gt;~ &amp;nbsp; future, but only extenuating circumstances would lead to a branch's
&lt;br&gt;~ &amp;nbsp; support being dropped earlier than the date listed.
&lt;br&gt;&lt;br&gt;~ &amp;nbsp; +--------------------------------------------------------------------+
&lt;br&gt;~ &amp;nbsp; | &amp;nbsp;Branch &amp;nbsp; | &amp;nbsp;Release &amp;nbsp;| &amp;nbsp;Type &amp;nbsp;| &amp;nbsp;Release date &amp;nbsp; | &amp;nbsp;Estimated EoL &amp;nbsp;|
&lt;br&gt;~ &amp;nbsp; |-----------+-----------+--------+-----------------+-----------------|
&lt;br&gt;~ &amp;nbsp; |RELENG_6 &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|n/a &amp;nbsp; &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|November 30, 2010|
&lt;br&gt;~ &amp;nbsp; |-----------+-----------+--------+-----------------+-----------------|
&lt;br&gt;~ &amp;nbsp; |RELENG_6_3 |6.3-RELEASE|Extended|January 18, 2008 |January 31, 2010 |
&lt;br&gt;~ &amp;nbsp; |-----------+-----------+--------+-----------------+-----------------|
&lt;br&gt;~ &amp;nbsp; |RELENG_6_4 |6.4-RELEASE|Extended|November 28, 2008|November 30, 2010|
&lt;br&gt;~ &amp;nbsp; |-----------+-----------+--------+-----------------+-----------------|
&lt;br&gt;~ &amp;nbsp; |RELENG_7 &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|n/a &amp;nbsp; &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|last release + 2y|
&lt;br&gt;~ &amp;nbsp; |-----------+-----------+--------+-----------------+-----------------|
&lt;br&gt;~ &amp;nbsp; |RELENG_7_1 |7.1-RELEASE|Extended|January 4, 2009 &amp;nbsp;|January 31, 2011 |
&lt;br&gt;~ &amp;nbsp; +--------------------------------------------------------------------+
&lt;br&gt;&lt;br&gt;[End excerpt]
&lt;br&gt;&lt;br&gt;- --
&lt;br&gt;Colin Percival
&lt;br&gt;Security Officer, FreeBSD | freebsd.org | The power to serve
&lt;br&gt;Founder / author, Tarsnap | tarsnap.com | Online backups for the truly paranoid
&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkn7rngACgkQFdaIBMps37IFxACgm/W0s1RMwBtYKHGGa3kk1FSi
&lt;br&gt;dwEAn1WIK57UMysjjrj304IySPnxLca9
&lt;br&gt;=veRi
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23342517&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23342517&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-supported-branches-update-tp23342517p23342517.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23178066</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:07.libc</title>
	<published>2009-04-22T07:19:12Z</published>
	<updated>2009-04-22T07:19:12Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:07.libc &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Information leak in db(3)
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; libc
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-04-22
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Jaakko Heinonen, Xin LI
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-04-11 15:19:26 UTC (RELENG_7, 7.2-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-04-22 14:07:14 UTC (RELENG_7_1, 7.1-RELEASE-p5)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-04-22 14:07:14 UTC (RELENG_7_0, 7.0-RELEASE-p12)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-04-11 15:21:11 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-04-22 14:07:14 UTC (RELENG_6_4, 6.4-RELEASE-p4)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-04-22 14:07:14 UTC (RELENG_6_3, 6.3-RELEASE-p10)
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;FreeBSD's C library (libc) contains code for creating and accessing
&lt;br&gt;Berkeley DB 1.85 database files. &amp;nbsp;Such databases are used extensively
&lt;br&gt;in FreeBSD; for example, the system password files (/etc/passwd and
&lt;br&gt;/etc/master.passwd) are normally accessed via their database files
&lt;br&gt;(/etc/pwd.db and /etc/spwd.db).
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;Some data structures used by the database interface code are not properly
&lt;br&gt;initialized when allocated.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;Programs using the db(3) interface to create Berkeley database files may
&lt;br&gt;&amp;quot;leak&amp;quot; sensitive information into database files. &amp;nbsp;If those files can be
&lt;br&gt;read by other users, this may result in the disclosure of sensitive
&lt;br&gt;information such as login credentials.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but systems without untrusted local users are
&lt;br&gt;probably not affected (since remote attackers will in most cases not be
&lt;br&gt;able to read such database files).
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_1, RELENG_7_0, RELENG_6_4, or RELENG_6_3 security branch
&lt;br&gt;dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;7.0, and 7.1 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:07/libc.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:07/libc.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:07/libc.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:07/libc.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/lib/libc
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;&lt;br&gt;NOTE: On the amd64 platform, the above procedure will not update the
&lt;br&gt;lib32 (i386 compatibility) libraries. &amp;nbsp;On amd64 systems where the i386
&lt;br&gt;compatibility libraries are used, the operating system should instead
&lt;br&gt;be recompiled as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/makeworld.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/makeworld.html&lt;/a&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;NOTE: System administrators may wish to rebuild any system database files
&lt;br&gt;which were created prior to applying this patch in case they contain
&lt;br&gt;sensitive information.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/lib/libc/db/btree/bt_split.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.7.2.1
&lt;br&gt;&amp;nbsp; src/lib/libc/db/btree/bt_open.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.11.14.1
&lt;br&gt;&amp;nbsp; src/lib/libc/db/hash/hash_buf.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.7.14.1
&lt;br&gt;&amp;nbsp; src/lib/libc/db/mpool/mpool.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.12.2.1
&lt;br&gt;&amp;nbsp; src/lib/libc/db/README &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.40.1
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.40.2.8
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.18.2.10
&lt;br&gt;&amp;nbsp; src/lib/libc/db/btree/bt_split.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.7.12.2
&lt;br&gt;&amp;nbsp; src/lib/libc/db/hash/hash_buf.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.7.26.2
&lt;br&gt;&amp;nbsp; src/lib/libc/db/mpool/mpool.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.12.12.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.15
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.14
&lt;br&gt;&amp;nbsp; src/lib/libc/db/btree/bt_split.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.7.10.1
&lt;br&gt;&amp;nbsp; src/lib/libc/db/hash/hash_buf.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.7.24.1
&lt;br&gt;&amp;nbsp; src/lib/libc/db/mpool/mpool.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.12.10.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/lib/libc/db/btree/bt_split.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.8.2.1 
&lt;br&gt;&amp;nbsp; src/lib/libc/db/btree/bt_open.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.12.2.1
&lt;br&gt;&amp;nbsp; src/lib/libc/db/hash/hash_buf.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.8.2.1
&lt;br&gt;&amp;nbsp; src/lib/libc/db/mpool/mpool.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.13.2.1 
&lt;br&gt;&amp;nbsp; src/lib/libc/db/README &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.50.1
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.8
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.9.2.9
&lt;br&gt;&amp;nbsp; src/lib/libc/db/btree/bt_split.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.8.6.2
&lt;br&gt;&amp;nbsp; src/lib/libc/db/hash/hash_buf.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.8.6.2
&lt;br&gt;&amp;nbsp; src/lib/libc/db/mpool/mpool.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.13.6.2
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.3.2.16
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.5.2.16
&lt;br&gt;&amp;nbsp; src/lib/libc/db/btree/bt_split.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.8.4.1
&lt;br&gt;&amp;nbsp; src/lib/libc/db/hash/hash_buf.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.8.4.1
&lt;br&gt;&amp;nbsp; src/lib/libc/db/mpool/mpool.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.13.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r190940
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r191381
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r191381
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r190939
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r191381
&lt;br&gt;releng/7.0/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r191381
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:07.libc.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:07.libc.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAknvJlkACgkQFdaIBMps37JcyACggmDk96JTy3G5gGlzMlNuVsV7
&lt;br&gt;s5wAoIT2G2c3T6bYa7GeftWLpGGFo2Rp
&lt;br&gt;=rdqD
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23178066&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23178066&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A07.libc-tp23178066p23178066.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23177816</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:08.openssl</title>
	<published>2009-04-22T07:19:08Z</published>
	<updated>2009-04-22T07:19:08Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:08.openssl &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Remotely exploitable crash in OpenSSL
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; openssl
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-04-22
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-04-22 14:07:14 UTC (RELENG_7, 7.2-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-04-22 14:07:14 UTC (RELENG_7_2, 7.2-RC2)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-04-22 14:07:14 UTC (RELENG_7_1, 7.1-RELEASE-p5)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-04-22 14:07:14 UTC (RELENG_7_0, 7.0-RELEASE-p12)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-04-22 14:07:14 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-04-22 14:07:14 UTC (RELENG_6_4, 6.4-RELEASE-p4)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-04-22 14:07:14 UTC (RELENG_6_3, 6.3-RELEASE-p10)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2009-0590
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;FreeBSD includes software from the OpenSSL Project. &amp;nbsp;The OpenSSL Project is
&lt;br&gt;a collaborative effort to develop a robust, commercial-grade, full-featured
&lt;br&gt;Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3)
&lt;br&gt;and Transport Layer Security (TLS v1) protocols as well as a full-strength
&lt;br&gt;general purpose cryptography library.
&lt;br&gt;&lt;br&gt;The function ASN1_STRING_print_ex is often used to print the contents of
&lt;br&gt;an SSL certificate.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;The function ASN1_STRING_print_ex does not properly validate the lengths
&lt;br&gt;of BMPString or UniversalString objects before attempting to print them.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;An application which attempts to print a BMPString or UniversalString
&lt;br&gt;which has an invalid length will crash as a result of OpenSSL accessing
&lt;br&gt;invalid memory locations. &amp;nbsp;This could be used by an attacker to crash a
&lt;br&gt;remote application.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but applications which do not use the
&lt;br&gt;ASN1_STRING_print_ex function (either directly or indirectly) are not
&lt;br&gt;affected.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_2, RELENG_7_1, RELENG_7_0, RELENG_6_4, or RELENG_6_3 security
&lt;br&gt;branch dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;7.0, 7.1, and 7.2 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 7.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:08/openssl.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:08/openssl.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:08/openssl.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:08/openssl.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 6.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:08/openssl6.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:08/openssl6.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:08/openssl6.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:08/openssl6.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/secure/lib/libcrypto
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make includes &amp;&amp; make &amp;&amp; make install
&lt;br&gt;&lt;br&gt;NOTE: On the amd64 platform, the above procedure will not update the
&lt;br&gt;lib32 (i386 compatibility) libraries. &amp;nbsp;On amd64 systems where the i386
&lt;br&gt;compatibility libraries are used, the operating system should instead
&lt;br&gt;be recompiled as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/makeworld.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/makeworld.html&lt;/a&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1_err.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.12.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/tasn_dec.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.10.2
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.7.10.1
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.40.2.8
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.18.2.10
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1_err.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.24.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/tasn_dec.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.10.1.6.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.7.22.1
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.15
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.14
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1_err.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.22.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/tasn_dec.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.10.1.4.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.7.20.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1_err.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.6.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/tasn_dec.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.2.2.1
&lt;br&gt;RELENG_7_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.23.2.2
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1_err.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.6.8.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/tasn_dec.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.8.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.2.8.1
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.8
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.9.2.9
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1_err.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.6.6.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/tasn_dec.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.6.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.2.6.1
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.3.2.16
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.5.2.16
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1_err.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.6.4.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/tasn_dec.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.4.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/crypto/asn1/asn1.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.2.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r191381
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r191381
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r191381
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r191381
&lt;br&gt;releng/7.2/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r191381
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r191381
&lt;br&gt;releng/7.0/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r191381
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://openssl.org/news/secadv_20090325.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://openssl.org/news/secadv_20090325.txt&lt;/a&gt;&lt;br&gt;[Note that two of the issues mentioned in the OpenSSL advisory do
&lt;br&gt;not affect FreeBSD.]
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0590&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0590&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:08.openssl.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:08.openssl.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAknvJegACgkQFdaIBMps37LB4gCffpTTOSdqyLK6ravrv6h8LqWE
&lt;br&gt;MDcAn2SIjNmRL8Oktk0l9hLz0mhtcxWP
&lt;br&gt;=Q7Zz
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23177816&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23177816&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A08.openssl-tp23177816p23177816.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22652509</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:06.ktimer</title>
	<published>2009-03-22T17:09:12Z</published>
	<updated>2009-03-22T17:09:12Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:06.ktimer &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local privilege escalation
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; kern
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-03-23
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FreeBSD 7.x
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-03-23 00:00:50 UTC (RELENG_7, 7.2-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-03-23 00:00:50 UTC (RELENG_7_1, 7.1-RELEASE-p4)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-03-23 00:00:50 UTC (RELENG_7_0, 7.0-RELEASE-p11)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2009-1041
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;In FreeBSD 7.0, support was introduced for per-process timers as defined
&lt;br&gt;in the POSIX realtime extensions. &amp;nbsp;This allows a process to have a limited
&lt;br&gt;number of timers running at once, with various actions taken when each
&lt;br&gt;timer reaches zero.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;An integer which specifies which timer a process wishes to operate upon is
&lt;br&gt;not properly bounds-checked.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;An unprivileged process can overwrite an arbitrary location in kernel
&lt;br&gt;memory. &amp;nbsp;This could be used to change the user ID of the process (in order
&lt;br&gt;to &amp;quot;become root&amp;quot;), to escape from a jail, or to bypass security mechanisms
&lt;br&gt;in other ways.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but systems without untrusted local users are
&lt;br&gt;not vulnerable.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 7-STABLE, or to the RELENG_7_1
&lt;br&gt;or RELENG_7_0 security branch dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patch has been verified to apply to FreeBSD 7.0 and 7.1
&lt;br&gt;systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:06/ktimer.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:06/ktimer.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:06/ktimer.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:06/ktimer.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_time.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.142.2.3
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.7
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.9.2.8
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_time.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.142.2.2.2.2
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.3.2.15
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.5.2.15
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_time.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.142.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r190301
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r190301
&lt;br&gt;releng/7.0/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r190301
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1041&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1041&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-06:09.ktimer.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-06:09.ktimer.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAknG0hQACgkQFdaIBMps37JA4gCfaznvIWKB/AU0cv6ojZUhheD4
&lt;br&gt;MuYAnAp3wuz3E7gIX6VK7PeUVnPp/41o
&lt;br&gt;=MPIX
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22652509&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22652509&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A06.ktimer-tp22652509p22652509.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22046975</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:05.telnetd</title>
	<published>2009-02-16T14:02:33Z</published>
	<updated>2009-02-16T14:02:33Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:05.telnetd &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;telnetd code execution vulnerability
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-02-16
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FreeBSD 7.x
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-02-16 21:56:17 UTC (RELENG_7, 7.1-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-02-16 21:56:17 UTC (RELENG_7_1, 7.1-RELEASE-p10)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-02-16 21:56:17 UTC (RELENG_7_0, 7.0-RELEASE-p3)
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;The FreeBSD telnet daemon, telnetd(8), implements the server side of the
&lt;br&gt;TELNET virtual terminal protocol. &amp;nbsp;It has been disabled by default in
&lt;br&gt;FreeBSD since August 2001, and due to the lack of cryptographic security
&lt;br&gt;in the TELNET protocol, it is strongly recommended that the SSH protocol
&lt;br&gt;be used instead. &amp;nbsp;The FreeBSD telnet daemon can be enabled via the
&lt;br&gt;/etc/inetd.conf configuration file and the inetd(8) daemon.
&lt;br&gt;&lt;br&gt;The TELNET protocol allows a connecting client to specify environment
&lt;br&gt;variables which should be set in any created login session; this is used,
&lt;br&gt;for example, to specify terminal settings.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;In order to prevent environment variable based attacks, telnetd(8) &amp;quot;scrubs&amp;quot;
&lt;br&gt;its environment; however, recent changes in FreeBSD's environment-handling
&lt;br&gt;code rendered telnetd's scrubbing inoperative, thereby allowing potentially
&lt;br&gt;harmful environment variables to be set.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;An attacker who can place a specially-constructed file onto a target system
&lt;br&gt;(either by legitimately logging into the system or by exploiting some other
&lt;br&gt;service on the system) can execute arbitrary code with the privileges of
&lt;br&gt;the user running the telnet daemon (usually root).
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but systems which are not running the telnet
&lt;br&gt;daemon are not vulnerable.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 7-STABLE, or to the RELENG_7_1 or
&lt;br&gt;RELENG_7_0 security branch dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 7.0 and 7.1
&lt;br&gt;systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:05/telnetd.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:05/telnetd.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:05/telnetd.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:05/telnetd.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/lib/libtelnet
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make
&lt;br&gt;# cd /usr/src/libexec/telnetd
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/contrib/telnet/telnetd/sys_term.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.18.22.1
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.6
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.9.2.7
&lt;br&gt;&amp;nbsp; src/contrib/telnet/telnetd/sys_term.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.18.30.2
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.3.2.14
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.5.2.14
&lt;br&gt;&amp;nbsp; src/contrib/telnet/telnetd/sys_term.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.18.26.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r188699
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r188699
&lt;br&gt;releng/7.0/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r188699
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://lists.grok.org.uk/pipermail/full-disclosure/2009-February/067954.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.grok.org.uk/pipermail/full-disclosure/2009-February/067954.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:05.telnetd.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:05.telnetd.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkmZ4dwACgkQFdaIBMps37JI2gCfZsCqw/ev/qVKELwNiFxj8zra
&lt;br&gt;aooAn0GU4wBW7jBulFhrSyXtKVlgs18B
&lt;br&gt;=joA6
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22046975&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=22046975&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A05.telnetd-tp22046975p22046975.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21446281</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:04.bind</title>
	<published>2009-01-13T14:33:57Z</published>
	<updated>2009-01-13T14:33:57Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:04.bind &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;BIND DNSSEC incorrect checks for malformed signatures
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; bind
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-01-13
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Google Security Team
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported FreeBSD versions
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-01-10 03:00:21 UTC (RELENG_7, 7.1-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-13 21:19:27 UTC (RELENG_7_1, 7.1-RELEASE-p2)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-13 21:19:27 UTC (RELENG_7_0, 7.0-RELEASE-p9)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-10 04:30:27 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-13 21:19:27 UTC (RELENG_6_4, 6.4-RELEASE-p3)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-13 21:19:27 UTC (RELENG_6_3, 6.3-RELEASE-p9)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2009-0025
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;BIND 9 is an implementation of the Domain Name System (DNS) protocols.
&lt;br&gt;The named(8) daemon is an Internet Domain Name Server. &amp;nbsp;DNS Security
&lt;br&gt;Extensions (DNSSEC) are additional protocol options that add
&lt;br&gt;authentication as part of responses to DNS queries.
&lt;br&gt;&lt;br&gt;FreeBSD includes software from the OpenSSL Project. &amp;nbsp;The OpenSSL
&lt;br&gt;Project is a collaborative effort to develop a robust,
&lt;br&gt;commercial-grade, full-featured Open Source toolkit implementing the
&lt;br&gt;Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1)
&lt;br&gt;protocols as well as a full-strength general purpose cryptography
&lt;br&gt;library.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;The DSA_do_verify() function from OpenSSL is used to determine if a
&lt;br&gt;DSA digital signature is valid. &amp;nbsp;When DNSSEC is used within BIND it
&lt;br&gt;uses DSA_do_verify() to verify DSA signatures, but checks the function
&lt;br&gt;return value incorrectly.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;It is in theory possible to spoof a DNS reply even though DNSSEC
&lt;br&gt;is set up to validate answers. &amp;nbsp;This could be used by an attacker for
&lt;br&gt;man-in-the-middle or other spoofing attacks.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;Disable the the DSA algorithm in named.conf. &amp;nbsp;This will cause answers
&lt;br&gt;from zones signed only with DSA to be treated as insecure. &amp;nbsp;Add the
&lt;br&gt;following to the options section of named.conf:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; disable-algorithms . { DSA; };
&lt;br&gt;&lt;br&gt;NOTE WELL: If named(8) is not explicitly set to use DNSSEC the setup is
&lt;br&gt;not vulnerable to the issue as described in this Security Advisory.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_1, RELENG_7_0, RELENG_6_4, or RELENG_6_3 security branch
&lt;br&gt;dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;7.0, and 7.1 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:04/bind.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:04/bind.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:04/bind.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:04/bind.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/lib/bind
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;# cd /usr/src/usr.sbin/named
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;# /etc/rc.d/named restart
&lt;br&gt;&lt;br&gt;c) Install and use a fixed version of BIND from the FreeBSD Ports
&lt;br&gt;Collection.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/contrib/bind9/CHANGES &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.10
&lt;br&gt;&amp;nbsp; src/contrib/bind9/FAQ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/FAQ.xml &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/README &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.6
&lt;br&gt;&amp;nbsp; src/contrib/bind9/aclocal.m4 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/dig.1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/dig.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/dig.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/dig.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/dighost.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/host.1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/host.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/host.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-keygen.8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-keygen.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-keygen.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-signzone.8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-signzone.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-signzone.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-signzone.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/client.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.7
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/config.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/controlconf.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/include/named/globals.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/interfacemgr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/lwresd.8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/lwresd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/lwresd.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/lwresd.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/main.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/named.8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/named.conf.5 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/named.conf.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/named.conf.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/named.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/named.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/query.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.6
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/server.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.6
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/unix/include/named/os.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/unix/os.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/update.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/nsupdate/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/nsupdate/nsupdate.1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/nsupdate/nsupdate.8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/nsupdate/nsupdate.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/nsupdate/nsupdate.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/rndc/rndc-confgen.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/rndc/rndc.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/config.h.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/configure.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.6
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/aclocal.m4 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/bsd/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/bsd/strerror.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/bsd/strtoul.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/config.h.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/configure.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/dst/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/dst/dst_api.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/dst/hmac_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/dst/support.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/include/arpa/nameser.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/include/isc/assertions.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/include/isc/misc.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/include/resolv.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/inet/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/inet/inet_net_pton.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/irs/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/irs/dns_ho.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/irs/irp.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/isc/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/isc/assertions.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/isc/bitncmp.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/isc/ctl_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/isc/ctl_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/nameser/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/port_after.h.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/resolv/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/resolv/res_debug.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/resolv/res_mkquery.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/resolv/res_query.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind9/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind9/check.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/adb.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.7
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/cache.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dispatch.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.6
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/include/dns/dispatch.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/journal.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/masterdump.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/message.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/openssldsa_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/opensslrsa_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rbt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rdata/generic/nsec_47.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rdata/generic/nsec_47.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rdata/generic/txt_16.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rdata/in_1/naptr_35.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/request.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/resolver.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.10
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/validator.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/view.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/xfrin.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/assertions.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/assertions.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/mem.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/msgs.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/platform.h.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/portset.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/resource.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/socket.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/timer.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/types.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/mem.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/portset.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/print.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/pthreads/mutex.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/timer.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/app.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/include/isc/net.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/net.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/resource.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/socket.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/socket_p.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/time.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isccfg/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isccfg/namedconf.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/version &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.10
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.40.2.6
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.18.2.9
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/opensslrsa_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.2.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/openssldsa_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.2.2.1
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.14
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.13
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/opensslrsa_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/openssldsa_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.4.1.2.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/contrib/bind9/CHANGES &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.10.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/COPYRIGHT &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/FAQ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.6.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/FAQ.xml &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/README &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.7.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/aclocal.m4 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/check/check-tool.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/check/named-checkconf.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/check/named-checkzone.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/dig.1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/dig.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/dig.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/dig.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/dighost.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/host.1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/host.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dig/host.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-keygen.8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-keygen.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-keygen.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-signzone.8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-signzone.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-signzone.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/dnssec/dnssec-signzone.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/client.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/config.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/controlconf.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/include/named/globals.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/interfacemgr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/lwaddr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/lwdgnba.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/lwdnoop.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/lwresd.8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/lwresd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/lwresd.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/lwresd.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/main.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/named.8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/named.conf.5 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/named.conf.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/named.conf.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/named.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/named.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/query.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.6.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/server.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/unix/include/named/os.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/unix/os.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/update.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/nsupdate/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/nsupdate/nsupdate.1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/nsupdate/nsupdate.8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/nsupdate/nsupdate.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/nsupdate/nsupdate.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/nsupdate/nsupdate.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/rndc/rndc-confgen.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/rndc/rndc.8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/rndc/rndc.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.6.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/rndc/rndc.docbook &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/rndc/rndc.html &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/config.h.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/configure.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/aclocal.m4 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.10.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/bsd/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/bsd/strerror.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/bsd/strtoul.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/config.h.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/configure.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/dst/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/dst/dst_api.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/dst/hmac_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/dst/support.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/include/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/include/arpa/nameser.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/include/isc/assertions.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/include/isc/eventlib.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/include/isc/misc.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/include/isc/platform.h.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/include/netdb.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/include/resolv.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/inet/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/inet/inet_net_pton.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/inet/inet_network.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/irs/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/irs/dns_ho.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/irs/getnetgrent.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/irs/getnetgrent_r.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/irs/irp.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/isc/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/isc/assertions.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/isc/bitncmp.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/isc/ctl_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/isc/ctl_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/isc/logging.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/nameser/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/port_after.h.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/port_before.h.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/resolv/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/resolv/res_debug.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/resolv/res_mkquery.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/resolv/res_query.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind/resolv/res_send.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind9/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/bind9/check.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/acache.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/adb.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.6.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/cache.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dispatch.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dst_parse.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dst_parse.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/include/dns/dispatch.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/journal.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/master.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/masterdump.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/message.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/openssldsa_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/opensslrsa_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rbt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rbtdb.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rdata/generic/nsec_47.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rdata/generic/nsec_47.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rdata/generic/txt_16.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rdata/in_1/apl_42.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rdata/in_1/naptr_35.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/request.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/resolver.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.9.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/rootns.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/sdb.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/tkey.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/tsig.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/validator.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.6.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/view.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/xfrin.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/zone.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/Makefile.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/assertions.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/assertions.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/lex.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/mem.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/msgs.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/platform.h.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/portset.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/resource.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/socket.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/timer.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/include/isc/types.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/mem.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/portset.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/print.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/pthreads/mutex.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/timer.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/app.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/include/isc/net.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/net.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/resource.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/socket.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/socket_p.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isc/unix/time.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isccfg/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/isccfg/namedconf.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/lwres/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/make/rules.in &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/version &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.10.2.4
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.5
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.9.2.6
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/opensslrsa_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.6.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/openssldsa_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.1.4.1
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.3.2.13
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.5.2.13
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/opensslrsa_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.4.4.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/openssldsa_link.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.2.1.2.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r187002
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r187194
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r187194
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186997
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r187194
&lt;br&gt;releng/7.0/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r187194
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0025&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0025&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:02.openssl.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:02.openssl.asc&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;https://www.isc.org/node/373&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.isc.org/node/373&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:04.bind.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:04.bind.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFJbRUmFdaIBMps37IRAonEAJsFQFtZGTz6tXFc5TSRMLhB1hxb6QCeI0Pd
&lt;br&gt;ZFPKsX8/XspOTzRWA1h3QPk=
&lt;br&gt;=dpqG
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21446281&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21446281&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A04.bind-tp21446281p21446281.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21446069</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:03.ntpd</title>
	<published>2009-01-13T14:33:21Z</published>
	<updated>2009-01-13T14:33:21Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:03.ntpd &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ntpd cryptographic signature bypass
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ntpd
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-01-13
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Google Security Team
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All FreeBSD releases
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-01-13 21:19:27 UTC (RELENG_7, 7.1-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-13 21:19:27 UTC (RELENG_7_1, 7.1-RELEASE-p2)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-13 21:19:27 UTC (RELENG_7_0, 7.0-RELEASE-p9)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-13 21:19:27 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-13 21:19:27 UTC (RELENG_6_4, 6.4-RELEASE-p3)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-13 21:19:27 UTC (RELENG_6_3, 6.3-RELEASE-p9)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2009-0021
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;The ntpd daemon is an implementation of the Network Time Protocol
&lt;br&gt;(NTP) used to synchronize the time of a computer system to a reference
&lt;br&gt;time source.
&lt;br&gt;&lt;br&gt;FreeBSD includes software from the OpenSSL Project. &amp;nbsp;The OpenSSL
&lt;br&gt;Project is a collaborative effort to develop a robust,
&lt;br&gt;commercial-grade, full-featured Open Source toolkit implementing the
&lt;br&gt;Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1)
&lt;br&gt;protocols as well as a full-strength general purpose cryptography
&lt;br&gt;library.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;The EVP_VerifyFinal() function from OpenSSL is used to determine if a
&lt;br&gt;digital signature is valid. &amp;nbsp;When ntpd(8) is set to cryptographically
&lt;br&gt;authenticate NTP data it incorrectly checks the return value from
&lt;br&gt;EVP_VerifyFinal().
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;An attacker which can send NTP packets to ntpd, which uses
&lt;br&gt;cryptographic authentication of NTP data, may be able to inject
&lt;br&gt;malicious time data causing the system clock to be set incorrectly.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;Use IP based restrictions in ntpd itself or in IP firewalls to
&lt;br&gt;restrict which systems can send NTP packets to ntpd.
&lt;br&gt;&lt;br&gt;NOTE WELL: If ntpd is not explicitly set to use cryptographic
&lt;br&gt;authentication of NTP data the setup is not vulnerable to the issue
&lt;br&gt;as described in this Security Advisory.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;NOTE WELL: Due to an error in building the updates, this fix is not
&lt;br&gt;available via freebsd-update at the time of this advisory. &amp;nbsp;We expect
&lt;br&gt;that this will be fixed within the next 48 hours.
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_1, RELENG_7_0, RELENG_6_4, or RELENG_6_3 security branch
&lt;br&gt;dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;7.0, and 7.1 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 6.4 and 7.1]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:03/ntpd.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:03/ntpd.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:03/ntpd.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:03/ntpd.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 6.3 and 7.0]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:03/ntpd63.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:03/ntpd63.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:03/ntpd63.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:03/ntpd63.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/usr.sbin/ntp/ntpd
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;# /etc/rc.d/ntpd restart
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/contrib/ntp/ntpd/ntp_crypto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.8.2
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.40.2.6
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.18.2.9
&lt;br&gt;&amp;nbsp; src/contrib/ntp/ntpd/ntp_crypto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.3.8.1.2.1
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.14
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.13
&lt;br&gt;&amp;nbsp; src/contrib/ntp/ntpd/ntp_crypto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.20.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/contrib/ntp/ntpd/ntp_crypto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.18.2
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.5
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.9.2.6
&lt;br&gt;&amp;nbsp; src/contrib/ntp/ntpd/ntp_crypto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.18.1.2.1
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.3.2.13
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.5.2.13
&lt;br&gt;&amp;nbsp; src/contrib/ntp/ntpd/ntp_crypto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.22.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r187194
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r187194
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r187194
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r187194
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r187194
&lt;br&gt;releng/7.0/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r187194
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0021&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0021&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:02.openssl.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:02.openssl.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:03.ntpd.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:03.ntpd.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFJbRUfFdaIBMps37IRAqdjAJ42YSH0bjaAJBEVyMM7/em/tu0xUQCfVPrs
&lt;br&gt;IrH0Qxo4slvboQHsy1PbkN4=
&lt;br&gt;=Q4rn
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21446069&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21446069&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A03.ntpd-tp21446069p21446069.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21341157</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:02.openssl</title>
	<published>2009-01-07T13:37:18Z</published>
	<updated>2009-01-07T13:37:18Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:02.openssl &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;OpenSSL incorrectly checks for malformed signatures
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; openssl
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-01-07
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Google Security Team
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All FreeBSD releases
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-01-07 21:03:41 UTC (RELENG_7, 7.1-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-07 20:17:55 UTC (RELENG_7_1, 7.1-RELEASE-p1)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-07 20:17:55 UTC (RELENG_7_0, 7.0-RELEASE-p8)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-07 20:17:55 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-07 20:17:55 UTC (RELENG_6_4, 6.4-RELEASE-p2)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-07 20:17:55 UTC (RELENG_6_3, 6.3-RELEASE-p8)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-5077
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;FreeBSD includes software from the OpenSSL Project. &amp;nbsp;The OpenSSL Project is
&lt;br&gt;a collaborative effort to develop a robust, commercial-grade, full-featured
&lt;br&gt;Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3)
&lt;br&gt;and Transport Layer Security (TLS v1) protocols as well as a full-strength
&lt;br&gt;general purpose cryptography library.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;The EVP_VerifyFinal() function from OpenSSL is used to determine if a
&lt;br&gt;digital signature is valid. &amp;nbsp;The SSL layer in OpenSSL uses
&lt;br&gt;EVP_VerifyFinal(), which in several places checks the return value
&lt;br&gt;incorrectly and treats verification errors as a good signature. &amp;nbsp;This
&lt;br&gt;is only a problem for DSA and ECDSA keys.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;For applications using OpenSSL for SSL connections, an invalid SSL
&lt;br&gt;certificate may be interpreted as valid. &amp;nbsp;This could for example be
&lt;br&gt;used by an attacker to perform a man-in-the-middle attack.
&lt;br&gt;&lt;br&gt;Other applications which use the OpenSSL EVP API may similarly be
&lt;br&gt;affected.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;For a server an RSA signed certificate may be used instead of DSA or
&lt;br&gt;ECDSA based certificate.
&lt;br&gt;&lt;br&gt;Note that Mozilla Firefox does not use OpenSSL and thus is not
&lt;br&gt;affected.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_1, RELENG_7_0, RELENG_6_4, or RELENG_6_3 security branch
&lt;br&gt;dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;7.0, and 7.1 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 7.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:02/openssl.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:02/openssl.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:02/openssl.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:02/openssl.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 6.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:02/openssl6.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:02/openssl6.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:02/openssl6.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:02/openssl6.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/secure/lib/libssl
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;# cd /usr/src/secure/usr.bin/openssl
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;&lt;br&gt;NOTE: On the amd64 platform, the above procedure will not update the
&lt;br&gt;lib32 (i386 compatibility) libraries. &amp;nbsp;On amd64 systems where the i386
&lt;br&gt;compatibility libraries are used, the operating system should instead
&lt;br&gt;be recompiled as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/makeworld.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/makeworld.html&lt;/a&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/speed.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.13.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/verify.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.12.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/x509.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.10.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/spkac.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.12.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s2_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.12.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s3_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.12.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s3_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.14.2.2
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s2_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.13.2.2
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.40.2.5
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.18.2.8
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/speed.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.13.12.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/verify.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.24.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/x509.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.10.12.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/spkac.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.24.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s2_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.12.12.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s3_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.12.12.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s3_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.14.2.1.6.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s2_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.13.2.1.6.1
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.13
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.12
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/speed.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.13.10.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/verify.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.22.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/x509.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.10.10.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/spkac.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.22.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s2_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.12.10.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s3_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.12.10.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s3_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.14.2.1.4.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s2_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.13.2.1.4.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/speed.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.15.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/verify.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/x509.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.11.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/spkac.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s2_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.13.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s3_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.14.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s3_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.17.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/ssltest.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.10.2.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s2_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.15.2.1
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.4
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.9.2.5
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/speed.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.15.6.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/verify.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.6.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/x509.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.11.6.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/spkac.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.6.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s2_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.13.6.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s3_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.14.6.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s3_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.17.6.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/ssltest.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.10.6.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s2_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.15.6.1
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.3.2.12
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.5.2.12
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/speed.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.15.4.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/verify.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.4.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/x509.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.11.4.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/apps/spkac.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.4.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s2_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.13.4.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s3_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.14.4.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s3_srvr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.17.4.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/ssltest.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.10.4.1
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/s2_clnt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.15.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186873
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186872
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186872
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186872
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186872
&lt;br&gt;releng/7.0/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186872
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.openssl.org/news/secadv_20090107.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org/news/secadv_20090107.txt&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:02.openssl.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:02.openssl.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFJZR5ZFdaIBMps37IRAofJAJ4lm2jGfsMo28c0W4zRkhZrKmttGwCgmdd9
&lt;br&gt;IvNUwk47W24SwhQAGH5+Ggw=
&lt;br&gt;=UHSl
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21341157&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21341157&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A02.openssl-tp21341157p21341157.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21340977</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-09:01.lukemftpd</title>
	<published>2009-01-07T13:36:20Z</published>
	<updated>2009-01-07T13:36:20Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-09:01.lukemftpd &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross-site request forgery in lukemftpd(8)
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lukemftpd
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-01-07
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Maksymilian Arciemowicz
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2009-01-07 20:17:55 UTC (RELENG_7, 7.1-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-07 20:17:55 UTC (RELENG_7_1, 7.1-RELEASE-p1)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-07 20:17:55 UTC (RELENG_7_0, 7.0-RELEASE-p8)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-07 20:17:55 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-07 20:17:55 UTC (RELENG_6_4, 6.4-RELEASE-p2)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-01-07 20:17:55 UTC (RELENG_6_3, 6.3-RELEASE-p8)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-4247
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;lukemftpd(8) is a general-purpose implementation of File Transfer Protocol
&lt;br&gt;(FTP) server that is shipped with the FreeBSD base system. &amp;nbsp;It is not enabled
&lt;br&gt;in default installations but can be enabled as either an inetd(8) server,
&lt;br&gt;or a standard-alone server.
&lt;br&gt;&lt;br&gt;A cross-site request forgery attack is a type of malicious exploit that is
&lt;br&gt;mainly targeted to a web browser, by tricking a user trusted by the site
&lt;br&gt;into visiting a specially crafted URL, which in turn executes a command
&lt;br&gt;which performs some privileged operations on behalf of the trusted user
&lt;br&gt;on the victim site.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;The lukemftpd(8) server splits long commands into several requests. &amp;nbsp;This
&lt;br&gt;may result in the server executing a command which is hidden inside
&lt;br&gt;another very long command.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;This could, with a specifically crafted command, be used in a
&lt;br&gt;cross-site request forgery attack.
&lt;br&gt;&lt;br&gt;FreeBSD systems running lukemftpd(8) server could act as a point of privilege
&lt;br&gt;escalation in an attack against users using web browser to access trusted
&lt;br&gt;FTP sites.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but systems not running FTP servers are
&lt;br&gt;not vulnerable. &amp;nbsp;Systems not running the FreeBSD lukemftpd(8) server are not
&lt;br&gt;affected, but users of other ftp daemons are advised to take care since
&lt;br&gt;several other ftp daemons are known to have related bugs.
&lt;br&gt;&lt;br&gt;NOTE WELL: lukemftpd(8) is a different implementation of an FTP server
&lt;br&gt;than ftpd(8).
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_1, RELENG_7_0, RELENG_6_4, or RELENG_6_3 security branch
&lt;br&gt;dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;7.0, and 7.1 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:01/lukemftpd.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:01/lukemftpd.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-09:01/lukemftpd.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-09:01/lukemftpd.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/libexec/lukemftpd
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/ftpcmd.y &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.2
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/extern.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/ftpd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.4.2.2
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.40.2.5
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.18.2.8
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/ftpcmd.y &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.1.6.1
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/extern.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.1.6.1
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/ftpd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.4.2.1.6.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.13
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.12
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/ftpcmd.y &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/extern.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.1.4.1
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/ftpd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.4.2.1.4.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/ftpcmd.y &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.2.1
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/extern.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.2.1
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/ftpd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.5.2.1
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.4
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.9.2.5
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/ftpcmd.y &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.6.1
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/extern.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.6.1
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/ftpd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.5.6.2
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.3.2.12
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.5.2.12
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/ftpcmd.y &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.4.1
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/extern.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.5.4.1
&lt;br&gt;&amp;nbsp; src/contrib/lukemftpd/src/ftpd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.5.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186872
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186872
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186872
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186872
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186872
&lt;br&gt;releng/7.0/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186872
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4247&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4247&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://security.freebsd.org/advisories/FreeBSD-SA-08:12.ftpd.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.freebsd.org/advisories/FreeBSD-SA-08:12.ftpd.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:01.lukemftpd.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-09:01.lukemftpd.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFJZR5UFdaIBMps37IRApUJAKCEGZggeEjPC67j5Tmxl2fEDJ9sIQCfTAKn
&lt;br&gt;vpOXC5jix3XiB7wxGKrvNJM=
&lt;br&gt;=qPEc
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21340977&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21340977&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-09%3A01.lukemftpd-tp21340977p21340977.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21138277</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:12.ftpd</title>
	<published>2008-12-22T17:39:29Z</published>
	<updated>2008-12-22T17:39:29Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08:12.ftpd &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Cross-site request forgery in ftpd(8)
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ftpd
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-12-23
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Maksymilian Arciemowicz
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-12-23 01:23:09 UTC (RELENG_7, 7.1-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-12-23 01:23:09 UTC (RELENG_7_1, 7.1-RC2)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-12-23 01:23:09 UTC (RELENG_7_0, 7.0-RELEASE-p7)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-12-23 01:23:09 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-12-23 01:23:09 UTC (RELENG_6_4, 6.4-RELEASE-p1)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-12-23 01:23:09 UTC (RELENG_6_3, 6.3-RELEASE-p7)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-4247
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;ftpd(8) is a general-purpose implementation of File Transfer Protocol (FTP)
&lt;br&gt;server that is shipped with the FreeBSD base system. &amp;nbsp;It is not enabled
&lt;br&gt;in default installations but can be enabled as either an inetd(8) server,
&lt;br&gt;or a standard-alone server.
&lt;br&gt;&lt;br&gt;A cross-site request forgery attack is a type of malicious exploit that is
&lt;br&gt;mainly targeted to a web browser, by tricking a user trusted by the site
&lt;br&gt;into visiting a specially crafted URL, which in turn executes a command
&lt;br&gt;which performs some privileged operations on behalf of the trusted user
&lt;br&gt;on the victim site.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;The ftpd(8) server splits long commands into several requests. &amp;nbsp;This
&lt;br&gt;may result in the server executing a command which is hidden inside
&lt;br&gt;another very long command.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;This could, with a specifically crafted command, be used in a
&lt;br&gt;cross-site request forgery attack.
&lt;br&gt;&lt;br&gt;FreeBSD systems running ftpd(8) server could act as a point of privilege
&lt;br&gt;escalation in an attack against users using web browser to access trusted
&lt;br&gt;FTP sites.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but systems not running FTP servers are
&lt;br&gt;not vulnerable. &amp;nbsp;Systems not running the FreeBSD ftp(8) server are not
&lt;br&gt;affected, but users of other ftp daemons are advised to take care
&lt;br&gt;since several other ftp daemons are known to have related bugs.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_1, RELENG_7_0, RELENG_6_4, or RELENG_6_3 security branch
&lt;br&gt;dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;7.0, and 7.1 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:12/ftpd.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:12/ftpd.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:12/ftpd.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:12/ftpd.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/libexec/ftpd
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/ftpcmd.y &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.64.2.3
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/extern.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.19.14.1
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/ftpd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.206.2.4
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.40.2.4
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.18.2.7
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/ftpcmd.y &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.64.2.2.4.2
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/extern.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.19.30.2
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/ftpd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.206.2.3.4.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.12
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.11
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/ftpcmd.y &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.64.2.2.2.1
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/extern.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.19.26.1
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/ftpd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.206.2.3.2.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/ftpcmd.y &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.66.2.1
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/extern.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.19.24.1
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/ftpd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.212.2.1
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.2
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/ftpcmd.y &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.66.6.2
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/extern.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.19.32.2
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/ftpd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.212.6.2
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.3.2.11
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.5.2.11
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/ftpcmd.y &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.66.4.1
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/extern.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.19.28.1
&lt;br&gt;&amp;nbsp; src/libexec/ftpd/ftpd.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.212.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186405
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186405
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186405
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186405
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186405
&lt;br&gt;releng/7.0/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186405
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4247&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4247&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:12.ftpd.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:12.ftpd.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAklQP8wACgkQFdaIBMps37ITvgCePP8oVI6cffvQu229Qg7eNshN
&lt;br&gt;A0kAn3A6kjr+QovEwOVKNzjow1aCtU8K
&lt;br&gt;=sDxD
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21138277&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21138277&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A12.ftpd-tp21138277p21138277.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21138238</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:13.protosw</title>
	<published>2008-12-22T17:39:23Z</published>
	<updated>2008-12-22T17:39:23Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08:13.protosw &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;netgraph / bluetooth privilege escalation
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sys_kern
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-12-23
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Christer Oberg
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All FreeBSD releases
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-12-23 01:23:09 UTC (RELENG_7, 7.1-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-12-23 01:23:09 UTC (RELENG_7_1, 7.1-RC2)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-12-23 01:23:09 UTC (RELENG_7_0, 7.0-RELEASE-p7)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-12-23 01:23:09 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-12-23 01:23:09 UTC (RELENG_6_4, 6.4-RELEASE-p1)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-12-23 01:23:09 UTC (RELENG_6_3, 6.3-RELEASE-p7)
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;The FreeBSD kernel provides support for a variety of different types of
&lt;br&gt;communications sockets, including IPv4, IPv6, ISDN, ATM, routing protocol,
&lt;br&gt;link-layer, netgraph(4), and bluetooth sockets. &amp;nbsp;As an early form of
&lt;br&gt;object-oriented design, much of the functionality specific to different
&lt;br&gt;types of sockets is abstracted via function pointers.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;Some function pointers for netgraph and bluetooth sockets are not
&lt;br&gt;properly initialized.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;A local user can cause the FreeBSD kernel to execute arbitrary code.
&lt;br&gt;This could be used by an attacker directly; or it could be used to gain
&lt;br&gt;root privilege or to escape from a jail.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but systems without local untrusted users
&lt;br&gt;are not vulnerable. &amp;nbsp;Furthermore, systems are not vulnerable if they
&lt;br&gt;have neither the ng_socket nor ng_bluetooth kernel modules loaded or
&lt;br&gt;compiled into the kernel.
&lt;br&gt;&lt;br&gt;Systems with the security.jail.socket_unixiproute_only sysctl set to
&lt;br&gt;1 (the default) are only vulnerable if they have local untrusted users
&lt;br&gt;outside of jails.
&lt;br&gt;&lt;br&gt;If the command
&lt;br&gt;# kldstat -v | grep ng_
&lt;br&gt;produces no output, the system is not vulnerable.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_0, RELENG_6_4, or RELENG_6_3 security branch dated after the
&lt;br&gt;correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3, 6.4,
&lt;br&gt;and 7.0 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 6.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:13/protosw6x.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:13/protosw6x.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:13/protosw6x.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:13/protosw6x.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 7.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:13/protosw.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:13/protosw.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:13/protosw.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:13/protosw.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;CVS:
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/sys/kern/uipc_domain.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.44.2.4
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.40.2.4
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.18.2.7
&lt;br&gt;&amp;nbsp; src/sys/kern/uipc_domain.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.44.2.3.6.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.12
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.11
&lt;br&gt;&amp;nbsp; src/sys/kern/uipc_domain.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.44.2.3.4.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/sys/kern/uipc_domain.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.51.2.2
&lt;br&gt;RELENG_7_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.13.2.2
&lt;br&gt;&amp;nbsp; src/sys/kern/uipc_domain.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.51.2.1.2.2
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.3.2.11
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.5.2.11
&lt;br&gt;&amp;nbsp; src/sys/kern/uipc_domain.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.51.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;Subversion:
&lt;br&gt;&lt;br&gt;Branch/path &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Revision
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;stable/6/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186405
&lt;br&gt;releng/6.4/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186405
&lt;br&gt;releng/6.3/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186405
&lt;br&gt;stable/7/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186405
&lt;br&gt;releng/7.1/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186405
&lt;br&gt;releng/7.0/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; r186405
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:13.protosw.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:13.protosw.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAklQP9QACgkQFdaIBMps37KL2gCfRlQ7kTB24DYnDEGRUC+px4bX
&lt;br&gt;214AoJJrJjaeS6ITyk73AL/OK+rNAM4u
&lt;br&gt;=7qyU
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21138238&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=21138238&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A13.protosw-tp21138238p21138238.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-20666083</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:11.arc4random</title>
	<published>2008-11-24T09:47:13Z</published>
	<updated>2008-11-24T09:47:13Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08.11.arc4random &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;arc4random(9) predictable sequence vulnerability
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sys
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-11-24
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Robert Woolley, Mark Murray, Maxim Dounin, Ruslan Ermilov
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-11-24 17:39:39 UTC (RELENG_7, 7.1-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-11-24 17:39:39 UTC (RELENG_7_0, 7.0-RELEASE-p6)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-11-24 17:39:39 UTC (RELENG_6, 6.4-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-11-24 17:39:39 UTC (RELENG_6_4, 6.4-RELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-11-24 17:39:39 UTC (RELENG_6_3, 6.3-RELEASE-p6)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-5162
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;arc4random(9) is a generic-purpose random number generator based on the
&lt;br&gt;key stream generator of the RC4 cipher. &amp;nbsp;It is expected to be
&lt;br&gt;cryptographically strong, and used throughout the FreeBSD kernel for a
&lt;br&gt;variety of purposes, some of which rely on its cryptographic strength.
&lt;br&gt;arc4random(9) is periodically reseeded with entropy from the FreeBSD
&lt;br&gt;kernel's Yarrow random number generator, which gathers entropy from a
&lt;br&gt;variety of sources including hardware interrupts. &amp;nbsp;During the boot
&lt;br&gt;process, additional entropy is provided to the Yarrow random number
&lt;br&gt;generator from userland, helping to ensure that adequate entropy is
&lt;br&gt;present for cryptographic purposes.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&amp;nbsp;
&lt;br&gt;When the arc4random(9) random number generator is initialized, there may
&lt;br&gt;be inadequate entropy to meet the needs of kernel systems which rely on
&lt;br&gt;arc4random(9); and it may take up to 5 minutes before arc4random(9) is
&lt;br&gt;reseeded with secure entropy from the Yarrow random number generator.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;All security-related kernel subsystems that rely on a quality random
&lt;br&gt;number generator are subject to a wide range of possible attacks for the
&lt;br&gt;300 seconds after boot or until 64k of random data is consumed. &amp;nbsp;The list
&lt;br&gt;includes:
&lt;br&gt;&lt;br&gt;* GEOM ELI providers with onetime keys. &amp;nbsp;When a provider is configured in
&lt;br&gt;&amp;nbsp; a way so that it gets attached at the same time during boot (e.g. it
&lt;br&gt;&amp;nbsp; uses the rc subsystem to initialize) it might be possible for an
&lt;br&gt;&amp;nbsp; attacker to recover the encrypted data.
&lt;br&gt;&lt;br&gt;* GEOM shsec providers. &amp;nbsp;The GEOM shsec subsytem is used to split a shared
&lt;br&gt;&amp;nbsp; secret between two providers so that it can be recovered when both of
&lt;br&gt;&amp;nbsp; them are present. &amp;nbsp;This is done by writing the random sequence to one
&lt;br&gt;&amp;nbsp; of providers while appending the result of the random sequence on the
&lt;br&gt;&amp;nbsp; other host to the original data. &amp;nbsp;If the provider was created within the
&lt;br&gt;&amp;nbsp; first 300 seconds after booting, it might be possible for an attacker
&lt;br&gt;&amp;nbsp; to extract the original data with access to only one of the two providers
&lt;br&gt;&amp;nbsp; between which the secret data is split.
&lt;br&gt;&lt;br&gt;* System processes started early after boot may receive predictable IDs.
&lt;br&gt;&lt;br&gt;* The 802.11 network stack uses arc4random(9) to generate initial vectors
&lt;br&gt;&amp;nbsp; (IV) for WEP encryption when operating in client mode and WEP
&lt;br&gt;&amp;nbsp; authentication challenges when operating in hostap mode, which may be
&lt;br&gt;&amp;nbsp; insecure.
&lt;br&gt;&lt;br&gt;* The IPv4, IPv6 and TCP/UDP protocol implementations rely on a quality
&lt;br&gt;&amp;nbsp; random number generator to produce unpredictable IP packet identifiers,
&lt;br&gt;&amp;nbsp; initial TCP sequence numbers and outgoing port numbers. &amp;nbsp;During the
&lt;br&gt;&amp;nbsp; first 300 seconds after booting, it may be easier for an attacker to
&lt;br&gt;&amp;nbsp; execute IP session hijacking, OS fingerprinting, idle scanning, or in
&lt;br&gt;&amp;nbsp; some cases DNS cache poisoning and blind TCP data injection attacks.
&lt;br&gt;&lt;br&gt;* The kernel RPC code uses arc4random(9) to retrieve transaction
&lt;br&gt;&amp;nbsp; identifiers, which might make RPC clients vulnerable to hijacking
&lt;br&gt;&amp;nbsp; attacks.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available for affected systems.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;NOTE WELL: Any GEOM shsec providers which were created or written to
&lt;br&gt;during the first 300 seconds after booting should be re-created after
&lt;br&gt;applying this security update.
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_0, or RELENG_6_3 security branch dated after the correction
&lt;br&gt;date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3 and
&lt;br&gt;7.0 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 7.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:11/arc4random.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:11/arc4random.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:11/arc4random.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:11/arc4random.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 6.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:11/arc4random6x.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:11/arc4random6x.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:11/arc4random6x.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:11/arc4random6x.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/sys/dev/random/randomdev.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.59.2.2
&lt;br&gt;&amp;nbsp; src/sys/dev/random/randomdev_soft.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.11.2.3
&lt;br&gt;RELENG_6_4
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.40.2.2
&lt;br&gt;&amp;nbsp; src/sys/dev/random/randomdev.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.59.2.1.8.2
&lt;br&gt;&amp;nbsp; src/sys/dev/random/randomdev_soft.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.11.2.2.6.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.11
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.15.2.10
&lt;br&gt;&amp;nbsp; src/sys/dev/random/randomdev.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.59.2.1.6.1
&lt;br&gt;&amp;nbsp; src/sys/dev/random/randomdev_soft.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.11.2.2.4.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/sys/dev/random/randomdev.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.61.2.1
&lt;br&gt;&amp;nbsp; src/sys/dev/random/randomdev_soft.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.15.2.1
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.507.2.3.2.10
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.72.2.5.2.10
&lt;br&gt;&amp;nbsp; src/sys/dev/random/randomdev.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.61.4.1
&lt;br&gt;&amp;nbsp; src/sys/dev/random/randomdev_soft.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.15.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5162&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5162&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:11.arc4random.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:11.arc4random.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkkq550ACgkQFdaIBMps37K3SwCfcj0iiFxH2tljR1N7/qhXWiW1
&lt;br&gt;N/cAoIjgcsh6sZG/upobud4TVme9QJPf
&lt;br&gt;=SKuK
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=20666083&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=20666083&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A11.arc4random-tp20666083p20666083.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-19771747</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:10.nd6</title>
	<published>2008-10-01T17:39:20Z</published>
	<updated>2008-10-01T17:39:20Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08:10.nd6 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IPv6 Neighbor Discovery Protocol routing vulnerability
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sys_netinet6
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-10-01
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;David Miles
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-10-01 00:32:59 UTC (RELENG_7, 7.1-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-10-01 00:32:59 UTC (RELENG_7_0, 7.0-RELEASE-p5)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-10-01 00:32:59 UTC (RELENG_6, 6.4-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-10-01 00:32:59 UTC (RELENG_6_3, 6.3-RELEASE-p5)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-2476
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;IPv6 nodes use the Neighbor Discovery protocol to determine the link-layer
&lt;br&gt;address of other nodes, find routers, and maintain reachability information.
&lt;br&gt;The Neighbor Discovery protocol uses Neighbor Solicitation (ICMPv6 type 135)
&lt;br&gt;to query target nodes for their link-layer addresses.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;IPv6 routers may allow &amp;quot;on-link&amp;quot; IPv6 nodes to create and update the
&lt;br&gt;router's neighbor cache and forwarding information. &amp;nbsp;A malicious IPv6 node
&lt;br&gt;sharing a common router but on a different physical segment from another
&lt;br&gt;node may be able to spoof Neighbor Discovery messages, allowing it to update
&lt;br&gt;router information for the victim node.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;An attacker on a different physical network connected to the same IPv6
&lt;br&gt;router as another node could redirect IPv6 traffic intended for that node.
&lt;br&gt;This could lead to denial of service or improper access to private network
&lt;br&gt;traffic.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;Firewall packet filters can be used to filter incoming Neighbor
&lt;br&gt;Solicitation messages but may interfere with normal IPv6 operation if not
&lt;br&gt;configured carefully.
&lt;br&gt;&lt;br&gt;Reverse path forwarding checks could be used to make gateways, such as
&lt;br&gt;routers or firewalls, drop Neighbor Solicitation messages from
&lt;br&gt;nodes with unexpected source addresses on a particular interface.
&lt;br&gt;&lt;br&gt;IPv6 router administrators are encouraged to read RFC 3756 for further
&lt;br&gt;discussion of Neighbor Discovery security implications.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;NOTE WELL: The solution described below causes IPv6 Neighbor Discovery
&lt;br&gt;Neighbor Solicitation messages from non-neighbors to be ignored.
&lt;br&gt;This can be re-enabled if required by setting the newly added
&lt;br&gt;net.inet6.icmp6.nd6_onlink_ns_rfc4861 sysctl to a non-zero value.
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_0, or RELENG_6_3 security branch dated after the correction
&lt;br&gt;date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3 and
&lt;br&gt;7.0 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 6.3]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:10/nd6-6.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:10/nd6-6.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:10/nd6-6.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:10/nd6-6.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 7.0]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:10/nd6-7.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:10/nd6-7.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:10/nd6-7.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:10/nd6-7.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.36.2.10
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6_proto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.32.2.10
&lt;br&gt;&amp;nbsp; src/sys/netinet6/nd6.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.19.2.4
&lt;br&gt;&amp;nbsp; src/sys/netinet6/nd6_nbr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.29.2.11
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.37.2.10
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.15.2.9
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.36.2.8.2.1
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6_proto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.32.2.8.2.1
&lt;br&gt;&amp;nbsp; src/sys/netinet6/nd6.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.19.2.2.6.1
&lt;br&gt;&amp;nbsp; src/sys/netinet6/nd6_nbr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.29.2.9.2.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.51.2.2
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6_proto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.46.2.3
&lt;br&gt;&amp;nbsp; src/sys/netinet6/nd6.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.21.2.2
&lt;br&gt;&amp;nbsp; src/sys/netinet6/nd6_nbr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.47.2.3
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.507.2.3.2.9
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.5.2.9
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.51.4.1
&lt;br&gt;&amp;nbsp; src/sys/netinet6/in6_proto.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.46.4.1
&lt;br&gt;&amp;nbsp; src/sys/netinet6/nd6.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.21.4.1
&lt;br&gt;&amp;nbsp; src/sys/netinet6/nd6_nbr.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.47.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2476&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2476&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.kb.cert.org/vuls/id/472363&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.kb.cert.org/vuls/id/472363&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:10.nd6.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:10.nd6.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkjkF2cACgkQFdaIBMps37KWWgCZAfug94zPIdkzW0tdIdSDzH/0
&lt;br&gt;j18AnjypvJrRtzeQqhJkRU9wQWozgWvj
&lt;br&gt;=ieTi
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=19771747&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=19771747&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A10.nd6-tp19771747p19771747.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-19297686</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:09.icmp6</title>
	<published>2008-09-03T13:13:20Z</published>
	<updated>2008-09-03T13:13:20Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08:09.icmp6 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Remote kernel panics on IPv6 connections
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sys_netinet6
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Tom Parker, Bjoern A. Zeeb
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-09-03 19:09:47 UTC (RELENG_7, 7.1-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-09-03 19:09:47 UTC (RELENG_7_0, 7.0-RELEASE-p4)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-09-03 19:09:47 UTC (RELENG_6, 6.4-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-09-03 19:09:47 UTC (RELENG_6_3, 6.3-RELEASE-p4)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-3530
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;IPv6 nodes use ICMPv6 amongst other things to report errors encountered
&lt;br&gt;while processing packets. &amp;nbsp;The 'Packet Too Big Message' is sent in
&lt;br&gt;case a node cannot forward a packet because the size of the packet is
&lt;br&gt;larger than the MTU of next-hop link.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;In case of an incoming ICMPv6 'Packet Too Big Message', there is an
&lt;br&gt;insufficient check on the proposed new MTU for a path to the destination.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;When the kernel is configured to process IPv6 packets and has active
&lt;br&gt;IPv6 TCP sockets, a specifically crafted ICMPv6 'Packet Too Big
&lt;br&gt;Message' could cause the TCP stack of the kernel to panic,
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;Systems without INET6 / IPv6 support are not vulnerable and neither
&lt;br&gt;are systems which do not listen on any IPv6 TCP sockets and have no
&lt;br&gt;active IPv6 connections.
&lt;br&gt;&lt;br&gt;Filter ICMPv6 'Packet Too Big Messages' using a firewall, but this
&lt;br&gt;will at the same time break PMTU support for IPv6 connections.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE or 7-STABLE, or to the
&lt;br&gt;RELENG_6_3 or RELENG_7_0 security branch dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3 and
&lt;br&gt;FreeBSD 7.0 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:09/icmp6.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:09/icmp6.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:09/icmp6.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:09/icmp6.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/sys/netinet6/icmp6.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.62.2.11
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.37.2.9
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.15.2.8
&lt;br&gt;&amp;nbsp; src/sys/netinet6/icmp6.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.62.2.9.2.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/sys/netinet6/icmp6.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.80.2.7
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.507.2.3.2.8
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.5.2.8
&lt;br&gt;&amp;nbsp; src/sys/netinet6/icmp6.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.80.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3530&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3530&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:09.icmp6.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:09.icmp6.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFIvu2hFdaIBMps37IRAjxxAJwIIXP+ALAZkvG5m687PC+92BtXTwCfUZdS
&lt;br&gt;AvvrO0r+UAa6bn1H9mFf9So=
&lt;br&gt;=MBB1
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=19297686&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=19297686&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A09.icmp6-tp19297686p19297686.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-19297559</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:08.nmount</title>
	<published>2008-09-03T13:13:13Z</published>
	<updated>2008-09-03T13:13:13Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08:08.nmount &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;nmount(2) local arbitrary code execution
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sys_kern
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;James Gritton
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FreeBSD 7.0-RELEASE, FreeBSD 7.0-STABLE
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-09-03 19:09:47 UTC (RELENG_7, 7.1-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-09-03 19:09:47 UTC (RELENG_7_0, 7.0-RELEASE-p4)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-3531
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;The mount(2) and nmount(2) system calls are used by various utilities
&lt;br&gt;in the base system to graft a file system object on to the file system
&lt;br&gt;tree to a given mount point. &amp;nbsp;It is possible to allow unprivileged
&lt;br&gt;users to utililize these system calls by setting the vfs.usermount
&lt;br&gt;sysctl(8) variable.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;Various user defined input such as mount points, devices, and mount
&lt;br&gt;options are prepared and passed as arguments to nmount(2) into the
&lt;br&gt;kernel. &amp;nbsp;Under certain error conditions, user defined data will be
&lt;br&gt;copied into a stack allocated buffer stored in the kernel without
&lt;br&gt;sufficient bounds checking.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;If the system is configured to allow unprivileged users to mount file
&lt;br&gt;systems, it is possible for a local adversary to exploit this
&lt;br&gt;vulnerability and execute code in the context of the kernel.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;It is possible to work around this issue by allowing only privileged
&lt;br&gt;users to mount file systems by running the following sysctl(8)
&lt;br&gt;command:
&lt;br&gt;&lt;br&gt;# sysctl vfs.usermount=0
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;NOTE WELL: Even with this fix allowing users to mount arbitrary media
&lt;br&gt;should not be considered safe. &amp;nbsp;Most of the file systems in FreeBSD
&lt;br&gt;was not built to protect safeguard against malicious devices. &amp;nbsp;While
&lt;br&gt;such bugs in file systems are fixed when found, a complete audit has
&lt;br&gt;not been perfomed on the file system code.
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 7-STABLE, or to the RELENG_7_0
&lt;br&gt;security branch dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 7.0 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:08/nmount.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:08/nmount.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:08/nmount.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:08/nmount.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/sys/kern/vfs_mount.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.265.2.10
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.507.2.3.2.8
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.5.2.8
&lt;br&gt;&amp;nbsp; src/sys/kern/vfs_mount.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.265.2.1.2.2
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3531&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3531&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:08.nmount.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:08.nmount.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFIvu2eFdaIBMps37IRAl9BAJ9Jnp+agN06pBkzPDwEnOT83MNd6QCghOFX
&lt;br&gt;yvNI1gVmhAQ7MXOUvPoLcLk=
&lt;br&gt;=EsCn
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=19297559&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=19297559&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A08.nmount-tp19297559p19297559.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-19297307</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:07.amd64</title>
	<published>2008-09-03T13:13:05Z</published>
	<updated>2008-09-03T13:13:05Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08:07.amd64 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;amd64 swapgs local privilege escalation
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sys_amd64_amd64
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-09-03
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Nate Eldredge
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported FreeBSD/amd64 versions.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-08-21 09:58:18 UTC (RELENG_7, 7.0-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-09-03 19:09:47 UTC (RELENG_7_0, 7.0-RELEASE-p4)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-09-03 19:09:47 UTC (RELENG_6, 6.4-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-09-03 19:09:47 UTC (RELENG_6_3, 6.3-RELEASE-p4)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-3890
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;FreeBSD/amd64 is commonly used on 64bit systems with AMD and Intel
&lt;br&gt;CPU's. &amp;nbsp;For Intel CPU's this architecture is known as EM64T or Intel
&lt;br&gt;64.
&lt;br&gt;&lt;br&gt;The gs segment CPU register is used by both user processes and the
&lt;br&gt;kernel to convieniently access state data. &amp;nbsp;User processes use it to
&lt;br&gt;manage per-thread data, and the kernel uses it to manage per-processor
&lt;br&gt;data. &amp;nbsp;As the processor enters and leaves the kernel it uses the
&lt;br&gt;'swapgs' instruction to toggle between the kernel and user values for
&lt;br&gt;the gs register.
&lt;br&gt;&lt;br&gt;The kernel stores critical information in its per-processor data
&lt;br&gt;block. &amp;nbsp;This includes the currently executing process and its
&lt;br&gt;credentials.
&lt;br&gt;&lt;br&gt;As the processor switches between user and kernel level, a number of
&lt;br&gt;checks are performed in order to implement the privilege protection
&lt;br&gt;system. &amp;nbsp;If the processor detects a problem while attempting to switch
&lt;br&gt;privilege levels it generates a trap - typically general protection
&lt;br&gt;fault (GPF). &amp;nbsp;In that case, the processor aborts the return to the
&lt;br&gt;user level process and re-enters the kernel. &amp;nbsp;The FreeBSD kernel
&lt;br&gt;allows the user process to be notified of such an event by a signal
&lt;br&gt;(SIGSEGV or SIGBUS).
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;If a General Protection Fault happens on a FreeBSD/amd64 system while
&lt;br&gt;it is returning from an interrupt, trap or system call, the swapgs CPU
&lt;br&gt;instruction may be called one extra time when it should not resulting
&lt;br&gt;in userland and kernel state being mixed.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;A local attacker can by causing a General Protection Fault while the
&lt;br&gt;kernel is returning from an interrupt, trap or system call while
&lt;br&gt;manipulating stack frames and, run arbitrary code with kernel
&lt;br&gt;privileges.
&lt;br&gt;&lt;br&gt;The vulnerability can be used to gain kernel / supervisor privilege.
&lt;br&gt;This can for example be used by normal users to gain root privileges,
&lt;br&gt;to break out of jails, or bypass Mandatory Access Control (MAC)
&lt;br&gt;restrictions.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but only systems running the 64 bit
&lt;br&gt;FreeSD/amd64 kernels are vulnerable.
&lt;br&gt;&lt;br&gt;Systems with 64 bit capable CPUs, but running the 32 bit FreeBSD/i386
&lt;br&gt;kernel are not vulnerable.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE, or 7-STABLE, or to the
&lt;br&gt;RELENG_7_0, or RELENG_6_3 security branch dated after the correction
&lt;br&gt;date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3 and
&lt;br&gt;7.0 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:07/amd64.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:07/amd64.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:07/amd64.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:07/amd64.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/sys/amd64/amd64/exception.S &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.125.2.3
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.37.2.9
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.15.2.8
&lt;br&gt;&amp;nbsp; src/sys/amd64/amd64/exception.S &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.125.2.2.2.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/sys/amd64/amd64/exception.S &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.129.2.2
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.507.2.3.2.8
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.5.2.8
&lt;br&gt;&amp;nbsp; src/sys/amd64/amd64/exception.S &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.129.2.1.2.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3890&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3890&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:07.amd64.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:07.amd64.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFIvu2TFdaIBMps37IRAqt8AJsGd/2WDuMZYUeOcVKekHEHZWRoMACdGnVs
&lt;br&gt;0JZMykjScj7GbrsOlOW3uQg=
&lt;br&gt;=bs1z
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=19297307&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=19297307&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A07.amd64-tp19297307p19297307.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-18432732</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:06.bind</title>
	<published>2008-07-13T12:10:05Z</published>
	<updated>2008-07-13T12:10:05Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08:06.bind &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;DNS cache poisoning
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; bind
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-07-13
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Dan Kaminsky
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported FreeBSD versions.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-07-12 10:07:33 UTC (RELENG_6, 6.3-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-07-13 18:42:38 UTC (RELENG_6_3, 6.3-RELEASE-p3)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-07-13 18:42:38 UTC (RELENG_7, 7.0-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-07-13 18:42:38 UTC (RELENG_7_0, 7.0-RELEASE-p3)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-1447
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;BIND 9 is an implementation of the Domain Name System (DNS) protocols.
&lt;br&gt;The named(8) daemon is an Internet Domain Name Server. &amp;nbsp;DNS requests
&lt;br&gt;contain a query id which is used to match a DNS request with the response
&lt;br&gt;and to make it harder for anybody but the DNS server which received the
&lt;br&gt;request to send a valid response.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;The BIND DNS implementation does not randomize the UDP source port when 
&lt;br&gt;doing remote queries, and the query id alone does not provide adequate
&lt;br&gt;randomization.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;The lack of source port randomization reduces the amount of data the
&lt;br&gt;attacker needs to guess in order to successfully execute a DNS cache
&lt;br&gt;poisoning attack. &amp;nbsp;This allows the attacker to influence or control
&lt;br&gt;the results of DNS queries being returned to users from target systems.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;Limiting the group of machines that can do recursive queries on the DNS
&lt;br&gt;server will make it more difficult, but not impossible, for this
&lt;br&gt;vulnerability to be exploited.
&lt;br&gt;&lt;br&gt;To limit the machines able to perform recursive queries, add an ACL in
&lt;br&gt;named.conf and limit recursion like the following:
&lt;br&gt;&lt;br&gt;acl example-acl {
&lt;br&gt;&amp;nbsp; &amp;nbsp;192.0.2.0/24;
&lt;br&gt;};
&lt;br&gt;&lt;br&gt;options {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; recursion yes;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; allow-recursion { example-acl; };
&lt;br&gt;};
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 6-STABLE or 7-STABLE, or to the
&lt;br&gt;RELENG_7_0 or RELENG_6_3 security branch dated after the correction
&lt;br&gt;date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 6.3 and
&lt;br&gt;7.0 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 6.3]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:06/bind63.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:06/bind63.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:06/bind63.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:06/bind63.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 7.0]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:06/bind7.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:06/bind7.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:06/bind7.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:06/bind7.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/lib/bind
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;# cd /usr/src/usr.sbin/named
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;&lt;br&gt;NOTE WELL: This update causes BIND to choose a new, random UDP port for
&lt;br&gt;each new query; this may cause problems for some network configurations,
&lt;br&gt;particularly if firewall(s) block incoming UDP packets on particular
&lt;br&gt;ports. &amp;nbsp;The avoid-v4-udp-ports and avoid-v6-udp-ports options should be
&lt;br&gt;used to avoid selecting random port numbers within a blocked range.
&lt;br&gt;&lt;br&gt;NOTE WELL: If a port number is specified via the query-source or
&lt;br&gt;query-source-v6 options to BIND, randomized port selection will not be
&lt;br&gt;used. &amp;nbsp;Consequently it is strongly recommended that these options not
&lt;br&gt;be used to specify fixed port numbers.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/client.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/server.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dispatch.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.4
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/include/dns/dispatch.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/resolver.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.8
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.37.2.8
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.15.2.7
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/client.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/server.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.2.2.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dispatch.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.2.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/include/dns/dispatch.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/resolver.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.6.2.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/client.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/server.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.6.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dispatch.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/include/dns/dispatch.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/resolver.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.9.2.2
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.507.2.3.2.7
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.5.2.7
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/client.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.2.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/server.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.6.2.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/api &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.6.2.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dispatch.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.4.2.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/include/dns/dispatch.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.3.2.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/resolver.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.9.2.1.2.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.kb.cert.org/vuls/id/800113&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.kb.cert.org/vuls/id/800113&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:06.bind.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:06.bind.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkh6UiMACgkQFdaIBMps37IE5ACfYzpWMhEXgWNdjwVlzd7JTwBS
&lt;br&gt;Eu0AnRIogMIJ3fjQF4hcymtdwR6buRNc
&lt;br&gt;=shnR
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18432732&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=18432732&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A06.bind-tp18432732p18432732.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-17615568</id>
	<title>FreeBSD supported branches update</title>
	<published>2008-06-02T20:32:37Z</published>
	<updated>2008-06-02T20:32:37Z</updated>
	<author>
		<name>FreeBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;Hello Everyone,
&lt;br&gt;&lt;br&gt;The branches supported by the FreeBSD Security Officer have been updated
&lt;br&gt;to reflect recent EoL (end-of-life) events. &amp;nbsp;The new list is below and
&lt;br&gt;at &amp;lt;URL: &lt;a href=&quot;http://security.freebsd.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.freebsd.org/&lt;/a&gt;&amp;nbsp;&amp;gt;. &amp;nbsp;FreeBSD 5.5, FreeBSD 6.1, and
&lt;br&gt;FreeBSD 6.2 have `expired' and are no longer supported effective June 1,
&lt;br&gt;2008. &amp;nbsp;Users of these releases are advised to upgrade promptly to FreeBSD
&lt;br&gt;6.3 or FreeBSD 7.0, either by downloading an updated source tree and
&lt;br&gt;building updates manually, or (for i386 and amd64 systems) using the
&lt;br&gt;FreeBSD Update utility as described in the FreeBSD 6.3 and FreeBSD 7.0
&lt;br&gt;release announcements.
&lt;br&gt;&lt;br&gt;This marks the end of support by the FreeBSD Security Team for the
&lt;br&gt;FreeBSD 5-STABLE branch, and at this time support for running software
&lt;br&gt;from the ports tree on FreeBSD 5.x is also ceasing: &amp;nbsp;Packages for binary
&lt;br&gt;installations will no longer be built for FreeBSD 5.5, building ports
&lt;br&gt;from source on FreeBSD 5.x will no longer be supported, and the ports
&lt;br&gt;INDEX will no longer be built and made available via portsnap or the
&lt;br&gt;'make fetchindex' target. &amp;nbsp;Patches for individual ports specific for
&lt;br&gt;their functioning on FreeBSD 5.5 may still be accepted at the discretion
&lt;br&gt;of the port maintainer.
&lt;br&gt;&lt;br&gt;[Excerpt from &lt;a href=&quot;http://security.freebsd.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.freebsd.org/&lt;/a&gt;&amp;nbsp;follows]
&lt;br&gt;&lt;br&gt;FreeBSD Security Advisories
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;The FreeBSD Security Officer provides security advisories for
&lt;br&gt;&amp;nbsp; &amp;nbsp;several branches of FreeBSD development. These are the -STABLE
&lt;br&gt;&amp;nbsp; &amp;nbsp;Branches and the Security Branches. (Advisories are not issued for
&lt;br&gt;&amp;nbsp; &amp;nbsp;the -CURRENT Branch.)
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;* There is usually only a single -STABLE branch, although during
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;the transition from one major development line to another
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(such as from FreeBSD 5.x to 6.x), there is a time span in
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;which there are two -STABLE branches. The -STABLE branch tags
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;have names like RELENG_6. The corresponding builds have names
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;like FreeBSD 6.1-STABLE.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;* Each FreeBSD Release has an associated Security Branch. The
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Branch tags have names like RELENG_6_1. The
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;corresponding builds have names like FreeBSD 6.1-RELEASE-p1.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Isses affecting the FreeBSD Ports Collection are covered in the
&lt;br&gt;&amp;nbsp; &amp;nbsp;FreeBSD VuXML document.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Each branch is supported by the Security Officer for a limited
&lt;br&gt;&amp;nbsp; &amp;nbsp;time only, and is designated as one of `Early adopter', `Normal',
&lt;br&gt;&amp;nbsp; &amp;nbsp;or `Extended'. &amp;nbsp;The designation is used as a guideline for
&lt;br&gt;&amp;nbsp; &amp;nbsp;determining the lifetime of the branch as follows.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Early adopter
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Releases which are published from the -CURRENT branch will be
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;supported by the Security Officer for a minimum of 6 months
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;after the release.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Normal
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Releases which are published from a -STABLE branch will be
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;supported by the Security Officer for a minimum of 12 months
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;after the release.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Extended
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Selected releases will be supported by the Security Officer
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;for a minimum of 24 months after the release.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;The current designation and estimated lifetimes of the currently
&lt;br&gt;&amp;nbsp; &amp;nbsp;supported branches are given below. &amp;nbsp;The Estimated EoL (end-of-life)
&lt;br&gt;&amp;nbsp; &amp;nbsp;column gives the earliest date on which that branch is likely to be
&lt;br&gt;&amp;nbsp; &amp;nbsp;dropped. &amp;nbsp;Please note that these dates may be extended into the
&lt;br&gt;&amp;nbsp; &amp;nbsp;future, but only extenuating circumstances would lead to a branch's
&lt;br&gt;&amp;nbsp; &amp;nbsp;support being dropped earlier than the date listed.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;+--------------------------------------------------------------------+
&lt;br&gt;&amp;nbsp; &amp;nbsp;| &amp;nbsp;Branch &amp;nbsp; | &amp;nbsp;Release &amp;nbsp;| &amp;nbsp;Type &amp;nbsp;| &amp;nbsp;Release date &amp;nbsp; | &amp;nbsp;Estimated EoL &amp;nbsp;|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|-----------+-----------+--------+-----------------+-----------------|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|RELENG_6 &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|n/a &amp;nbsp; &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|January 31, 2010 |
&lt;br&gt;&amp;nbsp; &amp;nbsp;|-----------+-----------+--------+-----------------+-----------------|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|RELENG_6_3 |6.3-RELEASE|Extended|January 18, 2008 |January 31, 2010 |
&lt;br&gt;&amp;nbsp; &amp;nbsp;|-----------+-----------+--------+-----------------+-----------------|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|RELENG_7 &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|n/a &amp;nbsp; &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|last release + 2y|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|-----------+-----------+--------+-----------------+-----------------|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|RELENG_7_0 |7.0-RELEASE|Normal &amp;nbsp;|February 27, 2008|February 28, 2009|
&lt;br&gt;&amp;nbsp; &amp;nbsp;+--------------------------------------------------------------------+
&lt;br&gt;&lt;br&gt;[End excerpt]
&lt;br&gt;&lt;br&gt;Colin Percival
&lt;br&gt;FreeBSD Security Officer
&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkhEe5MACgkQFdaIBMps37IXoQCbB3RkY/s2CA+o/OFkuC/1YvUV
&lt;br&gt;rY8An1JawL1x8DdUOlVUL0b2+9N4XZ2v
&lt;br&gt;=X+Zm
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17615568&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=17615568&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-supported-branches-update-tp17615568p17615568.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-16736320</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:05.openssh</title>
	<published>2008-04-16T17:14:55Z</published>
	<updated>2008-04-16T17:14:55Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08:05.openssh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;OpenSSH X11-forwarding privilege escalation
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; openssh
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-04-17
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Timo Juhani Lindfors
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-04-16 23:58:33 UTC (RELENG_7, 7.0-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-04-16 23:58:52 UTC (RELENG_7_0, 7.1-RELEASE-p1)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-04-16 23:59:35 UTC (RELENG_6, 6.3-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-04-16 23:59:48 UTC (RELENG_6_3, 6.3-RELEASE-p2)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-04-17 00:00:04 UTC (RELENG_6_2, 6.2-RELEASE-p12)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-04-17 00:00:28 UTC (RELENG_6_1, 6.1-RELEASE-p24)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-04-17 00:00:41 UTC (RELENG_5, 5.5-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-04-17 00:00:54 UTC (RELENG_5_5, 5.5-RELEASE-p20)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-1483
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;OpenSSH is an implementation of the SSH protocol suite, providing an
&lt;br&gt;encrypted and authenticated transport for a variety of services,
&lt;br&gt;including remote shell access. &amp;nbsp;The OpenSSH server daemon (sshd)
&lt;br&gt;provides support for the X11 protocol by binding to a port on the
&lt;br&gt;server and forwarding any connections which are made to that port.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;When logging in via SSH with X11-forwarding enabled, sshd(8) fails to
&lt;br&gt;correctly handle the case where it fails to bind to an IPv4 port but
&lt;br&gt;successfully binds to an IPv6 port. &amp;nbsp;In this case, applications which
&lt;br&gt;use X11 will connect to the IPv4 port, even though it had not been
&lt;br&gt;bound by sshd(8) and is therefore not being securely forwarded.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;A malicious user could listen for X11 connections on a unused IPv4
&lt;br&gt;port, e.g tcp port 6010. &amp;nbsp;When an unaware user logs in and sets up X11
&lt;br&gt;fowarding the malicious user can capture all X11 data send over the
&lt;br&gt;port, potentially disclosing sensitive information or allowing the
&lt;br&gt;execution of commands with the privileges of the user using the
&lt;br&gt;X11 forwarding.
&lt;br&gt;&lt;br&gt;NOTE WELL: FreeBSD ships with IPv6 enabled by default in the GENERIC
&lt;br&gt;and SMP kernels, so users are vulnerable even they have not explicitly
&lt;br&gt;enabled IPv6 networking.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;Disable support for IPv6 in the sshd(8) daemon by setting the option
&lt;br&gt;&amp;quot;AddressFamily inet&amp;quot; in /etc/ssh/sshd_config.
&lt;br&gt;&lt;br&gt;Disable support for X11 forwarding in the sshd(8) daemon by setting
&lt;br&gt;the option &amp;quot;X11Forwarding no&amp;quot; in /etc/ssh/sshd_config.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 5-STABLE, 6-STABLE, or 7-STABLE,
&lt;br&gt;or to the RELENG_7_0, RELENG_6_3, RELENG_6_2, RELENG_6_1, RELENG_5_5
&lt;br&gt;security branch dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patch has been verified to apply to FreeBSD 5.5, 6.1,
&lt;br&gt;6.2, 6.3, and 7.0 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:05/openssh.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:05/openssh.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:05/openssh.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:05/openssh.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/secure/lib/libssh
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;# cd /usr/src/secure/usr.sbin/sshd
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;# /etc/rc.d/sshd restart
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_5
&lt;br&gt;&amp;nbsp; src/crypto/openssh/channels.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.18.2.1
&lt;br&gt;RELENG_5_5
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.342.2.35.2.21
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.62.2.21.2.22
&lt;br&gt;&amp;nbsp; src/crypto/openssh/channels.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.18.8.1
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/crypto/openssh/channels.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.20.2.3
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.37.2.6
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.15.2.5
&lt;br&gt;&amp;nbsp; src/crypto/openssh/channels.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.20.2.2.4.1
&lt;br&gt;RELENG_6_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.29.2.16
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.13.2.15
&lt;br&gt;&amp;nbsp; src/crypto/openssh/channels.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.20.2.2.2.1
&lt;br&gt;RELENG_6_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.22.2.27
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.11.2.26
&lt;br&gt;&amp;nbsp; src/crypto/openssh/channels.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.20.2.1.4.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/crypto/openssh/channels.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.23.2.1
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.507.2.3.2.5
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.5.2.5
&lt;br&gt;&amp;nbsp; src/crypto/openssh/channels.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.23.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463011&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=463011&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1483&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1483&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.openssh.com/txt/release-5.0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssh.com/txt/release-5.0&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:05.openssh.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:05.openssh.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.7 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFIBpWTFdaIBMps37IRAomdAJ9hKgp/MG2PbVVojAMjCTtcY6T5HgCeNDxa
&lt;br&gt;iA55tmcA3GXbsXAd/flJZO4=
&lt;br&gt;=joYI
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=16736320&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=16736320&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A05.openssh-tp16736320p16736320.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-15479329</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:04.ipsec</title>
	<published>2008-02-14T04:11:31Z</published>
	<updated>2008-02-14T04:11:31Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08:04.ipsec &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;IPsec null pointer dereference panic
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ipsec
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-02-14
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Takashi Sogabe, Tatuya Jinmei
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FreeBSD 5.5
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-02-14 11:49:39 UTC (RELENG_5, 5.5-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-02-14 11:50:28 UTC (RELENG_5_5, 5.5-RELEASE-p19)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-0177
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;The IPsec suite of protocols provide network level security for IPv4
&lt;br&gt;and IPv6 packets. &amp;nbsp;FreeBSD includes software originally developed by
&lt;br&gt;the KAME project which implements the various protocols that make up
&lt;br&gt;IPsec.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;There is an improper reference to a data structure in the processing of
&lt;br&gt;IPsec packets, which can result in a NULL pointer being dereferenced.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;A single specifically crafted IPv6 packet could cause the kernel to panic,
&lt;br&gt;when the kernel had been configured to process IPsec and IPv6 traffic.
&lt;br&gt;&lt;br&gt;This requires IPSEC to be compiled into the kernel, it does not necessarily
&lt;br&gt;have to be configured at that point.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but kernels which does not include IPsec
&lt;br&gt;support are not vulnerable. &amp;nbsp;The GENERIC and SMP kernel configurations
&lt;br&gt;distributed with FreeBSD releases do not include IPsec support.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 5-STABLE, or to the RELENG_5_5
&lt;br&gt;security branch dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 5.5 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:04/ipsec.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:04/ipsec.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:04/ipsec.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:04/ipsec.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_5
&lt;br&gt;&amp;nbsp; src/sys/netinet6/ipcomp_input.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.7.4.2
&lt;br&gt;RELENG_5_5
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.342.2.35.2.20
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.62.2.21.2.21
&lt;br&gt;&amp;nbsp; src/sys/netinet6/ipcomp_input.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.7.4.1.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.kb.cert.org/vuls/id/110947&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.kb.cert.org/vuls/id/110947&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0177&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0177&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:04.ipsec.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:04.ipsec.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.8 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFHtC0HFdaIBMps37IRAt5gAKCGnYEX3r7n0Dsypmfv2m1J9pgICwCfd6uH
&lt;br&gt;Gy2w6OYNovnfrb7EN0jWCjM=
&lt;br&gt;=jHy3
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=15479329&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=15479329&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A04.ipsec-tp15479329p15479329.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-15479262</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:03.sendfile</title>
	<published>2008-02-14T04:10:42Z</published>
	<updated>2008-02-14T04:10:42Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08:03.sendfile &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;sendfile(2) write-only file permission bypass
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sys_kern
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-02-14
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Kostik Belousov
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-02-14 11:45:00 UTC (RELENG_7, 7.0-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-02-14 11:45:41 UTC (RELENG_7_0, 7.0-RELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-02-14 11:46:08 UTC (RELENG_6, 6.3-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-02-14 11:46:41 UTC (RELENG_6_3, 6.3-RELEASE-p1)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-02-14 11:47:06 UTC (RELENG_6_2, 6.2-RELEASE-p11)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-02-14 11:47:39 UTC (RELENG_6_1, 6.1-RELEASE-p23)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-02-14 11:49:39 UTC (RELENG_5, 5.5-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-02-14 11:50:28 UTC (RELENG_5_5, 5.5-RELEASE-p19)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-0777
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;The sendfile(2) system call allows a server application (such as a
&lt;br&gt;HTTP or FTP server) to transmit the contents of a file over a network
&lt;br&gt;connection without first copying it to application memory. &amp;nbsp;High
&lt;br&gt;performance servers such as the Apache HTTP Server and ftpd use sendfile.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;When a process opens a file (and other file system objects, such as
&lt;br&gt;directories), it specifies access flags indicating its intent to read,
&lt;br&gt;write, or perform other operations. &amp;nbsp;These flags are checked against
&lt;br&gt;file system permissions, and then stored in the resulting file
&lt;br&gt;descriptor to validate future operations against.
&lt;br&gt;&lt;br&gt;The sendfile(2) system call does not check the file descriptor access
&lt;br&gt;flags before sending data from a file.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;If a file is write-only, a user process can open the file and use
&lt;br&gt;sendfile to send the content of the file over a socket, even though the
&lt;br&gt;user does not have read access to the file, resulting in possible
&lt;br&gt;disclosure of sensitive information.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but systems are only vulnerable if
&lt;br&gt;write-only files exist, which are not widely used.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 5-STABLE, 6-STABLE, or
&lt;br&gt;7.0-PRERELEASE, or to the RELENG_7_0, RELENG_6_3, RELENG_6_2,
&lt;br&gt;RELENG_6_1, or RELENG_5_5 security branch dated after the correction
&lt;br&gt;date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 5.5, 6.1,
&lt;br&gt;6.2, 6.3, and 7.0 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 6.2, 6.3, and 7.0]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:03/sendfile.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:03/sendfile.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:03/sendfile.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:03/sendfile.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 6.1]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:03/sendfile61.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:03/sendfile61.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:03/sendfile61.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:03/sendfile61.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 5.5]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:03/sendfile55.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:03/sendfile55.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:03/sendfile55.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:03/sendfile55.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_5
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_descrip.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.243.2.11
&lt;br&gt;RELENG_5_5
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.342.2.35.2.20
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.62.2.21.2.21
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_descrip.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.243.2.9.2.1
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_descrip.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.279.2.16
&lt;br&gt;&amp;nbsp; src/sys/kern/uipc_syscalls.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.221.2.5
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.37.2.5
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.15.2.4
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_descrip.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.279.2.15.2.1
&lt;br&gt;&amp;nbsp; src/sys/kern/uipc_syscalls.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.221.2.4.4.1
&lt;br&gt;RELENG_6_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.29.2.15
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.13.2.14
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_descrip.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.279.2.9.2.1
&lt;br&gt;&amp;nbsp; src/sys/kern/uipc_syscalls.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.221.2.4.2.1
&lt;br&gt;RELENG_6_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.22.2.26
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.11.2.25
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_descrip.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.279.2.6.2.1
&lt;br&gt;&amp;nbsp; src/sys/kern/uipc_syscalls.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.221.2.1.2.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_descrip.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.313.2.1
&lt;br&gt;&amp;nbsp; src/sys/kern/uipc_syscalls.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.259.2.2
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.507.2.3.2.3
&lt;br&gt;&amp;nbsp; src/sys/kern/kern_descrip.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.313.4.1
&lt;br&gt;&amp;nbsp; src/sys/kern/uipc_syscalls.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.259.4.2
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0777&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0777&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:03.sendfile.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:03.sendfile.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.8 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFHtC0DFdaIBMps37IRAqp8AJ91+flnCIUSvKoFQyXfD1YTnPnuqgCcDiPJ
&lt;br&gt;SR4X1dNFENsHMq9ROrQhr1c=
&lt;br&gt;=TX1R
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=15479262&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=15479262&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A03.sendfile-tp15479262p15479262.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-14819843</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:02.libc</title>
	<published>2008-01-14T15:09:43Z</published>
	<updated>2008-01-14T15:09:43Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08:02.libc &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;inet_network() buffer overflow
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; libc
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-01-14
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Bjoern A. Zeeb and Nate Eldredge
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FreeBSD 6.2
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-01-14 22:57:45 UTC (RELENG_7, 7.0-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-01-14 22:55:54 UTC (RELENG_7_0, 7.0-RC2)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-01-14 22:56:05 UTC (RELENG_6, 6.3-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-01-14 22:56:18 UTC (RELENG_6_3, 6.3-RELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-01-14 22:56:44 UTC (RELENG_6_2, 6.2-RELEASE-p10)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-0122
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;The resolver is the part of libc that resolves hostnames (example.com) to
&lt;br&gt;internet protocol (IP) addresses (192.0.2.1) and vice versa.
&lt;br&gt;&lt;br&gt;The inet_network() function returns an in_addr_t representing the network
&lt;br&gt;address of the IP address given to inet_network() as a character string in
&lt;br&gt;the dot-notation.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;An off-by-one error in the inet_network() function could lead to memory
&lt;br&gt;corruption with certain inputs.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;For programs which passes untrusted data to inet_network(), an
&lt;br&gt;attacker may be able to overwrite a region of memory with user defined
&lt;br&gt;data by causing specially crafted input to be passed to
&lt;br&gt;inet_network().
&lt;br&gt;&lt;br&gt;Depending on the region of memory the attacker is able to overwrite,
&lt;br&gt;this might lead to a denial of service or potentially code execution
&lt;br&gt;in the program using inet_network().
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 7.0-PRERELEASE, or 6-STABLE, or
&lt;br&gt;to the, RELENG_7_0, RELENG_6_3, or RELENG_6_2 security branch dated
&lt;br&gt;after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 7.0, 6.3,
&lt;br&gt;or 6.2 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:02/libc.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:02/libc.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:02/libc.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:02/libc.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile the operating system as described in
&lt;br&gt;&amp;lt;URL: &lt;a href=&quot;http://www.freebsd.org/handbook/makeworld.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freebsd.org/handbook/makeworld.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/lib/libc/inet/inet_network.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.2.2.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.37.2.3
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.15.2.3
&lt;br&gt;&amp;nbsp; src/lib/libc/inet/inet_network.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.2.2.1.4.1
&lt;br&gt;RELENG_6_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.29.2.13
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.13.2.13
&lt;br&gt;&amp;nbsp; src/lib/libc/inet/inet_network.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.2.2.1.2.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/lib/libc/inet/inet_network.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.4.2.1
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.507.2.3.2.1
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.5.2.2
&lt;br&gt;&amp;nbsp; src/lib/libc/inet/inet_network.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.4.4.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0122&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0122&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:02.libc.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:02.libc.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.7 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFHi+ntFdaIBMps37IRAr+GAJ9YxPIsD5OeyYkrwo5auWKgQwZRywCdHSrY
&lt;br&gt;NsNxcHsgdo7divn+LEkQ9po=
&lt;br&gt;=3RQQ
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=14819843&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=14819843&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A02.libc-tp14819843p14819843.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-14819462</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-08:01.pty</title>
	<published>2008-01-14T15:09:39Z</published>
	<updated>2008-01-14T15:09:39Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-08:01.pty &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;pty snooping
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; libc_stdlib / libutil
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-01-14
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;John Baldwin
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FreeBSD 5.0 and later.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2008-01-14 22:57:45 UTC (RELENG_7, 7.0-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-01-14 22:55:54 UTC (RELENG_7_0, 7.0-RC2)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-01-14 22:56:05 UTC (RELENG_6, 6.3-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-01-14 22:56:18 UTC (RELENG_6_3, 6.3-RELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-01-14 22:56:44 UTC (RELENG_6_2, 6.2-RELEASE-p10)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-01-14 22:56:56 UTC (RELENG_6_1, 6.1-RELEASE-p22)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-01-14 22:57:06 UTC (RELENG_5, 5.5-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-01-14 22:57:19 UTC (RELENG_5_5, 5.5-RELEASE-p18)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2008-0216, CVE-2008-0217
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;pt_chown is a setuid root support utility used by grantpt(3) to change
&lt;br&gt;ownership of a tty.
&lt;br&gt;&lt;br&gt;openpty(3) is a support function in libutil which is used to obtain a
&lt;br&gt;pseudo-terminal.
&lt;br&gt;&lt;br&gt;script(1) is a utility which makes a typescript of everything printed
&lt;br&gt;on a terminal.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;Two issues exist in the FreeBSD pty handling.
&lt;br&gt;&lt;br&gt;If openpty(3) is called as non-root user the newly created
&lt;br&gt;pseudo-terminal is world readable and writeable. &amp;nbsp;While this is
&lt;br&gt;documented to be the case, script(1) still uses openpty(3) and
&lt;br&gt;script(1) may be used by non-root users [CVE-2008-0217].
&lt;br&gt;&lt;br&gt;The ptsname(3) function incorrectly extracts two characters from the
&lt;br&gt;name of a device node in /dev without verifying that it's actually
&lt;br&gt;operating on a valid pty which the calling user owns. &amp;nbsp;pt_chown uses
&lt;br&gt;the bad result from ptsname(3) to change ownership of a pty to the
&lt;br&gt;user calling pt_chown [CVE-2008-0216].
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;If an unprivileged user is running script(1), or another program which
&lt;br&gt;uses openpty(3), an attacker may snoop text which is printed to the
&lt;br&gt;users terminal.
&lt;br&gt;&lt;br&gt;If a malicious user has read access to a device node with characters
&lt;br&gt;in the device name that match the name of a pty, then the malicious user
&lt;br&gt;can read the content of the pty from another user. &amp;nbsp;The malicious user
&lt;br&gt;can open a lot of tty's resulting in a high probabilty of a new user
&lt;br&gt;obtaining the pty name of a &amp;quot;vulnerable&amp;quot; pty.
&lt;br&gt;&lt;br&gt;NOTE WELL: If a user snoops a pty the snooped text will not be shown
&lt;br&gt;to the real user, which in many cases mean the real owner of the pty
&lt;br&gt;will be able to know the attack is taking place.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;Do not run script(1) as a non-root user.
&lt;br&gt;&lt;br&gt;The ptsname(3) issue only affects FreeBSD 6.0 and newer.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 5-STABLE, 6-STABLE, or
&lt;br&gt;7.0-PRERELEASE, or to the RELENG_7_0, RELENG_6_3, RELENG_6_2,
&lt;br&gt;RELENG_6_1, or RELENG_5_5 security branch dated after the correction
&lt;br&gt;date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 5.5, 6.1,
&lt;br&gt;6.2, 6.3, and 7.0 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 5.5]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:01/pty5.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:01/pty5.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:01/pty5.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:01/pty5.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 6.x]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:01/pty6.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:01/pty6.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:01/pty6.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:01/pty6.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 7.0]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:01/pty7.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:01/pty7.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-08:01/pty7.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-08:01/pty7.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile the operating system as described in
&lt;br&gt;&amp;lt;URL: &lt;a href=&quot;http://www.freebsd.org/handbook/makeworld.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freebsd.org/handbook/makeworld.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_5
&lt;br&gt;&amp;nbsp; src/lib/libutil/pty.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.15.4.1
&lt;br&gt;RELENG_5_5
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.342.2.35.2.18
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.62.2.21.2.20
&lt;br&gt;&amp;nbsp; src/lib/libutil/pty.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.15.16.1
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/lib/libc/stdlib/grantpt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.4.2.2
&lt;br&gt;&amp;nbsp; src/lib/libutil/pty.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.15.10.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.37.2.3
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.15.2.3
&lt;br&gt;&amp;nbsp; src/lib/libc/stdlib/grantpt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.4.10.2
&lt;br&gt;&amp;nbsp; src/lib/libutil/pty.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.15.20.2
&lt;br&gt;RELENG_6_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.29.2.13
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.13.2.13
&lt;br&gt;&amp;nbsp; src/lib/libc/stdlib/grantpt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.4.8.1
&lt;br&gt;&amp;nbsp; src/lib/libutil/pty.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.15.18.1
&lt;br&gt;RELENG_6_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.22.2.24
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.11.2.24
&lt;br&gt;&amp;nbsp; src/lib/libc/stdlib/grantpt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.4.6.1
&lt;br&gt;&amp;nbsp; src/lib/libutil/pty.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.15.14.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/lib/libc/stdlib/grantpt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.7.2.4
&lt;br&gt;&amp;nbsp; src/lib/libutil/pty.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.17.2.3
&lt;br&gt;RELENG_7_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.507.2.3.2.1
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.72.2.5.2.2
&lt;br&gt;&amp;nbsp; src/lib/libc/stdlib/grantpt.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.7.2.2.2.2
&lt;br&gt;&amp;nbsp; src/lib/libutil/pty.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.17.2.2.2.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0216&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0216&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0217&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0217&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-08:01.pty.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.7 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFHi+nfFdaIBMps37IRAhtUAJ9GXtRjTIxcbrCOxoMnO50ZLc5mAgCdGSyO
&lt;br&gt;D83MVnUtP9rhzD2JfOPbaOw=
&lt;br&gt;=V/kt
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=14819462&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=14819462&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-08%3A01.pty-tp14819462p14819462.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-14029875</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-07:10.gtar</title>
	<published>2007-11-29T08:31:42Z</published>
	<updated>2007-11-29T08:31:42Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-07:10.gtar &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;gtar directory traversal vulnerability
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib_tar
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2007-11-29
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Dmitry V. Levinx
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FreeBSD 5.x releases
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2007-11-29 16:08:54 UTC (RELENG_5, 5.5-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-11-29 16:09:26 UTC (RELENG_5_5, 5.5-RELEASE-p17)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2007-4131
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;GNU tar (gtar) is a utility to create and extract &amp;quot;tape archives&amp;quot;,
&lt;br&gt;commonly known as tar files. &amp;nbsp;GNU tar is included in FreeBSD 5.x as
&lt;br&gt;/usr/bin/gtar.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;Insufficient sanity checking of paths containing '.' and '..' allows
&lt;br&gt;gtar to overwrite arbitrary files on the system.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;An attacker who can convince an user to extract a specially crafted
&lt;br&gt;archive can overwrite arbitrary files with the permissions of the user
&lt;br&gt;running gtar. &amp;nbsp;If that user is root, the attacker can overwrite any
&lt;br&gt;file on the system.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;Use &amp;quot;bsdtar&amp;quot;, which has been the default tar implementation since
&lt;br&gt;FreeBSD 5.3.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 5-STABLE, or to the RELENG_5_5
&lt;br&gt;security branch dated after the correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 5.5
&lt;br&gt;systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:10/gtar.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:10/gtar.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:10/gtar.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:10/gtar.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/gnu/usr.bin/tar
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_5
&lt;br&gt;&amp;nbsp; src/contrib/tar/src/misc.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.3.8.1
&lt;br&gt;RELENG_5_5
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.342.2.35.2.17
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.62.2.21.2.19
&lt;br&gt;&amp;nbsp; src/contrib/tar/src/misc.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.3.20.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4131&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4131&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-07:10.gtar.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-07:10.gtar.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.7 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFHTue3FdaIBMps37IRAgzFAKCMswqo5lH2+bb0yGRN+qhPqfBYlACfQ4+j
&lt;br&gt;Dq8Gbv9wz/AwDyAEZq2+1eQ=
&lt;br&gt;=1e8b
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=14029875&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=14029875&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-07%3A10.gtar-tp14029875p14029875.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-14029919</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-07:09.random</title>
	<published>2007-11-29T08:31:19Z</published>
	<updated>2007-11-29T08:31:19Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-07:09.random &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Random value disclosure
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sys_dev_random
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2007-11-29
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Robert Woolley
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2007-11-29 16:05:38 UTC (RELENG_7, 7.0-BETA4)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-11-29 16:06:12 UTC (RELENG_6, 6.3-PRERELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-11-29 16:06:54 UTC (RELENG_6_3, 6.3-RC2)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-11-29 16:07:30 UTC (RELENG_6_2, 6.2-RELEASE-p9)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-11-29 16:07:54 UTC (RELENG_6_1, 6.1-RELEASE-p21)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-11-29 16:08:54 UTC (RELENG_5, 5.5-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-11-29 16:09:26 UTC (RELENG_5_5, 5.5-RELEASE-p17)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2007-6150
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;The random(4) and urandom(4) devices return an endless supply of
&lt;br&gt;pseudo-random bytes when read. &amp;nbsp;Cryptographic algorithms often depend
&lt;br&gt;on the secrecy of these pseudo-random values for security.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;Under certain circumstances, a bug in the internal state tracking on
&lt;br&gt;the random(4) and urandom(4) devices can be exploited to allow replaying
&lt;br&gt;of data distributed during subsequent reads.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;This could enable an adversary to determine fragments of random values
&lt;br&gt;previously read, allowing them to defeat certain security mechanisms.
&lt;br&gt;Note that the attacker has to be in close proximity to the source of
&lt;br&gt;the pseudo-randomness, which typically means local access to the system.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 5-STABLE, or 6-STABLE, or to the
&lt;br&gt;RELENG_6_2, RELENG_6_1, or RELENG_5_5 security branch dated after the
&lt;br&gt;correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 5.5, 6.1,
&lt;br&gt;and 6.2 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:09/random.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:09/random.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:09/random.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:09/random.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Apply the patch.
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;&lt;br&gt;c) Recompile your kernel as described in
&lt;br&gt;&amp;lt;URL:&lt;a href=&quot;http://www.FreeBSD.org/handbook/kernelconfig.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.FreeBSD.org/handbook/kernelconfig.html&lt;/a&gt;&amp;gt; and reboot the
&lt;br&gt;system.
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_5
&lt;br&gt;&amp;nbsp; src/sys/dev/random/yarrow.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.44.2.1
&lt;br&gt;RELENG_5_5
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.342.2.35.2.17
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.62.2.21.2.19
&lt;br&gt;&amp;nbsp; src/sys/dev/random/yarrow.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.44.8.1
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/sys/dev/random/yarrow.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.45.2.2
&lt;br&gt;RELENG_6_3
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.37.2.2
&lt;br&gt;&amp;nbsp; src/sys/dev/random/yarrow.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.45.2.1.6.1
&lt;br&gt;RELENG_6_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.29.2.12
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.13.2.12
&lt;br&gt;&amp;nbsp; src/sys/dev/random/yarrow.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.45.2.1.4.1
&lt;br&gt;RELENG_6_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.22.2.23
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.11.2.23
&lt;br&gt;&amp;nbsp; src/sys/dev/random/yarrow.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.45.2.1.2.1
&lt;br&gt;RELENG_7
&lt;br&gt;&amp;nbsp; src/sys/dev/random/yarrow.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.47.2.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6150&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6150&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-07:09.random.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-07:09.random.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.7 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFHTuezFdaIBMps37IRAhp3AJ0UHJiYycOQCEai3Aid2uT6Jf3WZwCfdR65
&lt;br&gt;Ozmn0Qn6Ru54NRriBJG1o4g=
&lt;br&gt;=95t9
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=14029919&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=14029919&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-07%3A09.random-tp14029919p14029919.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-13028915</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-07:08.openssl</title>
	<published>2007-10-03T15:58:30Z</published>
	<updated>2007-10-03T15:58:30Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-07:08.openssl &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Buffer overflow in OpenSSL SSL_get_shared_ciphers()
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; openssl
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2007-10-03
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Moritz Jodeit
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All FreeBSD releases.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2007-10-03 21:39:43 UTC (RELENG_6, 6.2-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-10-03 21:40:35 UTC (RELENG_6_2, 6.2-RELEASE-p8)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-10-03 21:41:22 UTC (RELENG_6_1, 6.1-RELEASE-p20)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-10-03 21:42:00 UTC (RELENG_5, 5.5-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-10-03 21:42:32 UTC (RELENG_5_5, 5.5-RELEASE-p16)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2007-5135
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;FreeBSD includes software from the OpenSSL Project. &amp;nbsp;The OpenSSL Project is
&lt;br&gt;a collaborative effort to develop a robust, commercial-grade, full-featured,
&lt;br&gt;and Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3)
&lt;br&gt;and Transport Layer Security (TLS v1) protocols as well as a full-strength
&lt;br&gt;general purpose cryptography library.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;A buffer overflow addressed in FreeBSD-SA-06:23.openssl has been found
&lt;br&gt;to be incorrectly fixed.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;For applications using the SSL_get_shared_ciphers() function, the
&lt;br&gt;buffer overflow could allow an attacker to crash or potentially
&lt;br&gt;execute arbitrary code with the permissions of the user running the
&lt;br&gt;application.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available, but only applications using the
&lt;br&gt;SSL_get_shared_ciphers() function are affected.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 5-STABLE, or 6-STABLE, or to the
&lt;br&gt;RELENG_6_2, RELENG_6_1, or RELENG_5_5 security branch dated after the
&lt;br&gt;correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patch have been verified to apply to FreeBSD 5.5, 6.1,
&lt;br&gt;and 6.2 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:08/openssl.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:08/openssl.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:08/openssl.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:08/openssl.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/secure/lib/libssl
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_5
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/ssl_lib.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.11.2.3
&lt;br&gt;RELENG_5_5
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.342.2.35.2.16
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.62.2.21.2.18
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/ssl_lib.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.11.2.1.4.2
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/ssl_lib.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.12.2.2
&lt;br&gt;RELENG_6_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.29.2.11
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.13.2.11
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/ssl_lib.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.12.2.1.2.1
&lt;br&gt;RELENG_6_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.22.2.22
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.11.2.22
&lt;br&gt;&amp;nbsp; src/crypto/openssl/ssl/ssl_lib.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.12.6.2
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://marc.info/?l=bugtraq&amp;m=119091888624735&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://marc.info/?l=bugtraq&amp;m=119091888624735&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5135&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5135&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-07:08.openssl.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-07:08.openssl.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.7 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFHBA+HFdaIBMps37IRAtTQAJ0bFBZt7DVJzhQkUcu7VdNS7Kj8cwCeMQaS
&lt;br&gt;cNFjW3j2eolZhlee83l3blo=
&lt;br&gt;=zwC2
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=13028915&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=13028915&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-07%3A08.openssl-tp13028915p13028915.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-11954702</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-07:07.bind</title>
	<published>2007-08-01T15:27:29Z</published>
	<updated>2007-08-01T15:27:29Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-07:07.bind &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Predictable query ids in named(8)
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; bind
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2007-08-01
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Amit Klein
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;FreeBSD 5.3 and later.
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2007-07-25 08:23:08 UTC (RELENG_6, 6.2-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-08-01 20:44:58 UTC (RELENG_6_2, 6.2-RELEASE-p7)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-08-01 20:45:49 UTC (RELENG_6_1, 6.1-RELEASE-p19)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-07-25 08:24:40 UTC (RELENG_5, 5.5-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-08-01 20:48:19 UTC (RELENG_5_5, 5.5-RELEASE-p15)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2007-2926
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;BIND 9 is an implementation of the Domain Name System (DNS) protocols.
&lt;br&gt;The named(8) daemon is an Internet Domain Name Server. &amp;nbsp;DNS requests
&lt;br&gt;contain a query id which is used match a DNS request with the response
&lt;br&gt;and to make it harder for anybody but the DNS server which received the
&lt;br&gt;request to send a valid response.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;When named(8) is operating as a recursive DNS server or sending NOTIFY
&lt;br&gt;requests to slave DNS servers, named(8) uses a predictable query id.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;An attacker who can see the query id for some request(s) sent by named(8)
&lt;br&gt;is likely to be able to perform DNS cache poisoning by predicting the
&lt;br&gt;query id for other request(s).
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 5-STABLE, or 6-STABLE, or to the
&lt;br&gt;RELENG_6_2, RELENG_6_1, or RELENG_5_5 security branch dated after the
&lt;br&gt;correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 5.5, 6.1,
&lt;br&gt;and 6.2 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:07/bind.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:07/bind.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:07/bind.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:07/bind.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/lib/bind
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;# cd /usr/src/usr.sbin/named
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/client.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.2.5
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dispatch.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/include/dns/dispatch.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.2.2
&lt;br&gt;RELENG_5_5
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.342.2.35.2.15
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.62.2.21.2.17
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/client.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.2.3.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dispatch.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.2.1.6.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/include/dns/dispatch.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.2.1.6.1
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/client.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.3
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dispatch.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/include/dns/dispatch.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.4.1
&lt;br&gt;RELENG_6_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.29.2.10
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.13.2.10
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/client.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1.4.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dispatch.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.10.2
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/include/dns/dispatch.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.1.10.1
&lt;br&gt;RELENG_6_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.22.2.21
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.11.2.21
&lt;br&gt;&amp;nbsp; src/contrib/bind9/bin/named/client.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.2.2.1.2.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/dispatch.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.8.1
&lt;br&gt;&amp;nbsp; src/contrib/bind9/lib/dns/include/dns/dispatch.h &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.1.1.1.8.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2926&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2926&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.isc.org/sw/bind/bind-security.php&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.isc.org/sw/bind/bind-security.php&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.trusteer.com/docs/bind9dns_s.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.trusteer.com/docs/bind9dns_s.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-07:07.bind.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-07:07.bind.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.7 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFGsPfzFdaIBMps37IRAgIfAJ9cO2LUUc0eb8T+6pltpha91wR2IgCeITpx
&lt;br&gt;H3SHyAkPMSICqnT9nY/UBE8=
&lt;br&gt;=Fop4
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=11954702&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=11954702&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-07%3A07.bind-tp11954702p11954702.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-11954458</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-07:06.tcpdump</title>
	<published>2007-08-01T15:27:00Z</published>
	<updated>2007-08-01T15:27:00Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-07:06.tcpdump &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Buffer overflow in tcpdump(1)
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; contrib
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; tcpdump
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2007-08-01
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;quot;mu-b&amp;quot;
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All supported versions of FreeBSD
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2007-08-01 20:42:48 UTC (RELENG_6, 6.2-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-08-01 20:44:58 UTC (RELENG_6_2, 6.2-RELEASE-p7)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-08-01 20:45:49 UTC (RELENG_6_1, 6.1-RELEASE-p19)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-08-01 20:47:13 UTC (RELENG_5, 5.5-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-08-01 20:48:19 UTC (RELENG_5_5, 5.5-RELEASE-p15)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2007-3798
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;Tcpdump is a commonly used network diagnostic utility which decodes packets
&lt;br&gt;received on the wire into human readable format.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;An un-checked return value in the BGP dissector code can result in an integer
&lt;br&gt;overflow. &amp;nbsp;This value is used in subsequent buffer management operations,
&lt;br&gt;resulting in a stack based buffer overflow under certain circumstances.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;By crafting malicious BGP packets, an attacker could exploit this vulnerability
&lt;br&gt;to execute code or crash the tcpdump process on the target system. &amp;nbsp;This
&lt;br&gt;code would be executed in the context of the user running tcpdump(1).
&lt;br&gt;It should be noted that tcpdump(1) requires privileges in order to open live
&lt;br&gt;network interfaces.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;No workaround is available.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 5-STABLE, or 6-STABLE, or to the
&lt;br&gt;RELENG_6_2, RELENG_6_1, or RELENG_5_5 security branch dated after the
&lt;br&gt;correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 5.5, 6.1,
&lt;br&gt;and 6.2 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:06/tcpdump.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:06/tcpdump.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:06/tcpdump.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:06/tcpdump.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# cd /usr/src/usr.sbin/tcpdump/tcpdump
&lt;br&gt;# make obj &amp;&amp; make depend &amp;&amp; make &amp;&amp; make install
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_5
&lt;br&gt;&amp;nbsp; src/contrib/tcpdump/print-bgp.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.2
&lt;br&gt;RELENG_5_5
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.342.2.35.2.15
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.62.2.21.2.17
&lt;br&gt;&amp;nbsp; src/contrib/tcpdump/print-bgp.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.5.2.1.2.1
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/contrib/tcpdump/print-bgp.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.8.2.1
&lt;br&gt;RELENG_6_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.29.2.10
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.13.2.10
&lt;br&gt;&amp;nbsp; src/contrib/tcpdump/print-bgp.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.8.8.1
&lt;br&gt;RELENG_6_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.22.2.21
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.11.2.21
&lt;br&gt;&amp;nbsp; src/contrib/tcpdump/print-bgp.c &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.1.1.8.6.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3798&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3798&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-07:06.tcpdump.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-07:06.tcpdump.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.7 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFGsPfwFdaIBMps37IRAmK/AJ0adsy8zlOOXaJhJJdcX6A0Uy+bSQCfQYVi
&lt;br&gt;4qk7MNSrKFZotejLEXKMCYI=
&lt;br&gt;=JIZh
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=11954458&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=11954458&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-07%3A06.tcpdump-tp11954458p11954458.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-11954382</id>
	<title>FreeBSD Security Advisory FreeBSD-SA-07:01.jail</title>
	<published>2007-08-01T15:26:08Z</published>
	<updated>2007-08-01T15:26:08Z</updated>
	<author>
		<name>FreeBSD Security Advisories</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;=============================================================================
&lt;br&gt;FreeBSD-SA-07:01.jail &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Security Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The FreeBSD Project
&lt;br&gt;&lt;br&gt;Topic: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Jail rc.d script privilege escalation
&lt;br&gt;&lt;br&gt;Category: &amp;nbsp; &amp;nbsp; &amp;nbsp; core
&lt;br&gt;Module: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; etc_rc.d
&lt;br&gt;Announced: &amp;nbsp; &amp;nbsp; &amp;nbsp;2007-01-11
&lt;br&gt;Credits: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Dirk Engling
&lt;br&gt;Affects: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;All FreeBSD releases since 5.3
&lt;br&gt;Corrected: &amp;nbsp; &amp;nbsp; &amp;nbsp;2007-01-11 18:16:58 UTC (RELENG_6, 6.2-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-01-11 18:17:24 UTC (RELENG_6_2, 6.2-RELEASE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-01-11 18:18:08 UTC (RELENG_6_1, 6.1-RELEASE-p12)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-01-11 18:18:35 UTC (RELENG_6_0, 6.0-RELEASE-p17)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-08-01 20:47:13 UTC (RELENG_5, 5.5-STABLE)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2007-08-01 20:48:19 UTC (RELENG_5_5, 5.5-RELEASE-p15)
&lt;br&gt;CVE Name: &amp;nbsp; &amp;nbsp; &amp;nbsp; CVE-2007-0166
&lt;br&gt;&lt;br&gt;For general information regarding FreeBSD Security Advisories,
&lt;br&gt;including descriptions of the fields above, security branches, and the
&lt;br&gt;following sections, please visit &amp;lt;URL:&lt;a href=&quot;http://security.FreeBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/&lt;/a&gt;&amp;gt;.
&lt;br&gt;&lt;br&gt;0. &amp;nbsp; Revision History
&lt;br&gt;&lt;br&gt;v1.0 2007-01-11 &amp;nbsp;Initial release.
&lt;br&gt;v1.1 2007-08-01 &amp;nbsp;Corrected patch for FreeBSD 5.5.
&lt;br&gt;&lt;br&gt;I. &amp;nbsp; Background
&lt;br&gt;&lt;br&gt;The jail(2) system call allows a system administrator to lock a process
&lt;br&gt;and all of its descendants inside an environment with a very limited
&lt;br&gt;ability to affect the system outside that environment, even for
&lt;br&gt;processes with superuser privileges. &amp;nbsp;It is an extension of, but
&lt;br&gt;far more powerful than, the traditional UNIX chroot(2) system call.
&lt;br&gt;&lt;br&gt;The host's jail rc.d(8) script can be used to start and stop jails
&lt;br&gt;automatically on system boot/shutdown.
&lt;br&gt;&lt;br&gt;II. &amp;nbsp;Problem Description
&lt;br&gt;&lt;br&gt;In multiple situations the host's jail rc.d(8) script does not check if
&lt;br&gt;a path inside the jail file system structure is a symbolic link before
&lt;br&gt;using the path. &amp;nbsp;In particular this is the case when writing the
&lt;br&gt;output from the jail start-up to /var/log/console.log and when
&lt;br&gt;mounting and unmounting file systems inside the jail directory
&lt;br&gt;structure.
&lt;br&gt;&lt;br&gt;III. Impact
&lt;br&gt;&lt;br&gt;Due to the lack of handling of potential symbolic links the host's jail
&lt;br&gt;rc.d(8) script is vulnerable to &amp;quot;symlink attacks&amp;quot;. &amp;nbsp;By replacing
&lt;br&gt;/var/log/console.log inside the jail with a symbolic link it is
&lt;br&gt;possible for the superuser (root) inside the jail to overwrite files
&lt;br&gt;on the host system outside the jail with arbitrary content. &amp;nbsp;This in
&lt;br&gt;turn can be used to execute arbitrary commands with non-jailed
&lt;br&gt;superuser privileges.
&lt;br&gt;&lt;br&gt;Similarly, by changing directory mount points inside the jail file
&lt;br&gt;system structure into symbolic links, it may be possible for a jailed
&lt;br&gt;attacker to mount file systems which were meant to be mounted inside
&lt;br&gt;the jail at arbitrary points in the host file system structure, or to
&lt;br&gt;unmount arbitrary file systems on the host system.
&lt;br&gt;&lt;br&gt;NOTE WELL: The above vulnerabilities occur only when a jail is being
&lt;br&gt;started or stopped using the host's jail rc.d(8) script; once started
&lt;br&gt;(and until stopped), running jails cannot exploit this.
&lt;br&gt;&lt;br&gt;IV. &amp;nbsp;Workaround
&lt;br&gt;&lt;br&gt;If the sysctl(8) variable security.jail.chflags_allowed is set to 0
&lt;br&gt;(the default), setting the &amp;quot;sunlnk&amp;quot; system flag on /var, /var/log,
&lt;br&gt;/var/log/console.log, and all file system mount points and their
&lt;br&gt;parent directories inside the jail(s) will ensure that the console
&lt;br&gt;log file and mount points are not replaced by symbolic links. &amp;nbsp;If
&lt;br&gt;this is done while jails are running, the administrator must check
&lt;br&gt;that an attacker has not replaced any directories with symlinks
&lt;br&gt;after setting the &amp;quot;sunlnk&amp;quot; flag.
&lt;br&gt;&lt;br&gt;V. &amp;nbsp; Solution
&lt;br&gt;&lt;br&gt;NOTE WELL: The solution described changes the default location of the
&lt;br&gt;&amp;quot;console.log&amp;quot; for jails from /var/log/console.log inside each jail to
&lt;br&gt;/var/log/jail_${jail_name}_console.log on host system. &amp;nbsp;If this is a
&lt;br&gt;problem, it may be possible to create a hard link from the new position
&lt;br&gt;of the console log file to a location inside the jail. &amp;nbsp;A new rc.conf(5)
&lt;br&gt;variable, jail_${jail_name}_consolelog, can be used to change the
&lt;br&gt;location of console.log files on a per-jail basis.
&lt;br&gt;&lt;br&gt;In addition, the solution described below does not fully secure jail
&lt;br&gt;configurations where two jails have overlapping directory trees and a
&lt;br&gt;file system is mounted inside the overlap. &amp;nbsp;Overlapping directory
&lt;br&gt;trees can occur when jails share the same root directory; when a jail
&lt;br&gt;has a root directory which is a subdirectory of another jail's root
&lt;br&gt;directory; or when a part of the file system space of one jail is
&lt;br&gt;mounted inside the file system space of another jail, e.g., using
&lt;br&gt;nullfs or unionfs.
&lt;br&gt;&lt;br&gt;To handle overlapping jails safely the administrator must set the
&lt;br&gt;sysctl(8) variable security.jail.chflags_allowed to 0 (the default)
&lt;br&gt;and manually set the &amp;quot;sunlnk&amp;quot; file/directory flag on all mount points
&lt;br&gt;and all parent directories of mount points. &amp;nbsp;If this is done while
&lt;br&gt;jails are running, the adminstrator must check that an attacker has
&lt;br&gt;not replaced any directories with symlinks after setting the &amp;quot;sunlnk&amp;quot;
&lt;br&gt;flag.
&lt;br&gt;&lt;br&gt;Perform one of the following:
&lt;br&gt;&lt;br&gt;1) Upgrade your vulnerable system to 5-STABLE, or 6-STABLE, or to the
&lt;br&gt;RELENG_6_1, RELENG_6_0, or RELENG_5_5 security branch dated after the
&lt;br&gt;correction date.
&lt;br&gt;&lt;br&gt;2) To patch your present system:
&lt;br&gt;&lt;br&gt;The following patches have been verified to apply to FreeBSD 5.5, 6.0,
&lt;br&gt;and 6.1 systems.
&lt;br&gt;&lt;br&gt;a) Download the relevant patch from the location below, and verify the
&lt;br&gt;detached PGP signature using your PGP utility.
&lt;br&gt;&lt;br&gt;[FreeBSD 5.5]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:01/jail5.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:01/jail5.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:01/jail5.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:01/jail5.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 6.0]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:01/jail60.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:01/jail60.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:01/jail60.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:01/jail60.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;[FreeBSD 6.1]
&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:01/jail61.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:01/jail61.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:01/jail61.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:01/jail61.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;NOTE: The patch distributed at the time of the original advisory was
&lt;br&gt;incorrect for FreeBSD 5.5 (both RELENG_5 and RELENG_5_5). &amp;nbsp;Systems to
&lt;br&gt;which the original patch was applied should be patched with the
&lt;br&gt;following corrective patch, which contains only the changes between
&lt;br&gt;the original and updated patch:
&lt;br&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:01/jail5-correction.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:01/jail5-correction.patch&lt;/a&gt;&lt;br&gt;# fetch &lt;a href=&quot;http://security.FreeBSD.org/patches/SA-07:01/jail5-correction.patch.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/patches/SA-07:01/jail5-correction.patch.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;b) Execute the following commands as root:
&lt;br&gt;&lt;br&gt;# cd /usr/src
&lt;br&gt;# patch &amp;lt; /path/to/patch
&lt;br&gt;# install -o root -g wheel -m 555 etc/rc.d/jail /etc/rc.d
&lt;br&gt;&lt;br&gt;VI. &amp;nbsp;Correction details
&lt;br&gt;&lt;br&gt;The following list contains the revision numbers of each file that was
&lt;br&gt;corrected in FreeBSD.
&lt;br&gt;&lt;br&gt;Branch &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Revision
&lt;br&gt;&amp;nbsp; Path
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;RELENG_5
&lt;br&gt;&amp;nbsp; src/etc/rc.d/jail &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.15.2.7
&lt;br&gt;RELENG_5_5
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.342.2.35.2.15
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.62.2.21.2.17
&lt;br&gt;&amp;nbsp; src/etc/rc.d/jail &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.15.2.5.2.2
&lt;br&gt;RELENG_6
&lt;br&gt;&amp;nbsp; src/etc/rc.d/jail &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.23.2.9
&lt;br&gt;RELENG_6_2
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.29.2.2
&lt;br&gt;&amp;nbsp; src/etc/rc.d/jail &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.23.2.7.2.1
&lt;br&gt;RELENG_6_1
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.416.2.22.2.14
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.69.2.11.2.14
&lt;br&gt;&amp;nbsp; src/etc/rc.d/jail &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.23.2.3.2.3
&lt;br&gt;RELENG_6_0
&lt;br&gt;&amp;nbsp; src/UPDATING &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.416.2.3.2.22
&lt;br&gt;&amp;nbsp; src/sys/conf/newvers.sh &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1.69.2.8.2.18
&lt;br&gt;&amp;nbsp; src/etc/rc.d/jail &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.23.2.2.2.1
&lt;br&gt;- -------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;VII. References
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0166&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0166&lt;/a&gt;&lt;br&gt;&lt;br&gt;The latest revision of this advisory is available at
&lt;br&gt;&lt;a href=&quot;http://security.FreeBSD.org/advisories/FreeBSD-SA-07:01.jail.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://security.FreeBSD.org/advisories/FreeBSD-SA-07:01.jail.asc&lt;/a&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.7 (FreeBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFGsPfrFdaIBMps37IRAgksAJ4yGy3zTBcr2N+TbDoTlN3aHUA8QQCgi/8B
&lt;br&gt;It4pOMoA0QMzAp8HxUWo+xU=
&lt;br&gt;=9tTT
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=11954382&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security-notifications&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=11954382&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-notifications-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-Security-Advisory-FreeBSD-SA-07%3A01.jail-tp11954382p11954382.html" />
</entry>

</feed>
