<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-12292</id>
	<title>Nabble - netbsd-announce</title>
	<updated>2009-09-25T10:43:36Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/netbsd-announce-f12292.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/netbsd-announce-f12292.html" />
	<subtitle type="html">This mailing list is for announcements about NetBSD.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-25617309</id>
	<title>nyftp.netbsd.org outage through 2009-09-28</title>
	<published>2009-09-25T10:43:36Z</published>
	<updated>2009-09-25T10:43:36Z</updated>
	<author>
		<name>Thor Lancelot Simon-3</name>
	</author>
	<content type="html">The air conditioning repairs at our facility in New York will extend
&lt;br&gt;through at least 2009-09-27. &amp;nbsp;Consequently the services hosted there
&lt;br&gt;will not be available until 2009-09-28 at the earliest.
&lt;br&gt;&lt;br&gt;We apologize again for the short notice; once again, it's all we had
&lt;br&gt;ourselves.
&lt;br&gt;&lt;br&gt;Thor
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/nyftp.netbsd.org-outage-2009-09-25-tp25603366p25617309.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25603366</id>
	<title>nyftp.netbsd.org outage 2009-09-25</title>
	<published>2009-09-24T14:55:38Z</published>
	<updated>2009-09-24T14:55:38Z</updated>
	<author>
		<name>Thor Lancelot Simon-3</name>
	</author>
	<content type="html">Around 00:00 UTC on 2009-09-25, nyftp.netbsd.org will be offline for an
&lt;br&gt;unknown interval of time due to the emergency replacement of a chiller
&lt;br&gt;and other air conditioning equipment at the location where it is hosted.
&lt;br&gt;We expect that the outage should be less than one full day.
&lt;br&gt;&lt;br&gt;We apologize for the short notice.
&lt;br&gt;&lt;br&gt;Thor
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/nyftp.netbsd.org-outage-2009-09-25-tp25603366p25603366.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25461900</id>
	<title>change of List-Id: format</title>
	<published>2009-09-15T14:02:17Z</published>
	<updated>2009-09-15T14:02:17Z</updated>
	<author>
		<name>spz</name>
	</author>
	<content type="html">Dear all,
&lt;br&gt;&lt;br&gt;the format of the List-Id field in the headers of NetBSD list mail
&lt;br&gt;will change to include a '.NetBSD.org' after the list name.
&lt;br&gt;If you are filtering by this field, please adjust.
&lt;br&gt;&lt;br&gt;regards,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; spz
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/change-of-List-Id%3A-format-tp25461900p25461900.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25301289</id>
	<title>NetBSD Core Team Changes</title>
	<published>2009-09-04T13:12:40Z</published>
	<updated>2009-09-04T13:12:40Z</updated>
	<author>
		<name>Alistair G. Crooks</name>
	</author>
	<content type="html">After almost two years on the NetBSD core team, Quentin Garnier
&lt;br&gt;(&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25301289&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cube@...&lt;/a&gt;) has decided to step down. &amp;nbsp;The Board of Directors &amp;nbsp;
&lt;br&gt;would like to thank him for doing a difficult job very well -
&lt;br&gt;Quentin's technical acumen is very widely respected, and his ability
&lt;br&gt;to get to the heart of technical issues is a fundamental part of his
&lt;br&gt;effectiveness on core. &amp;nbsp;He will be missed.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;The Board of Directors has asked Matt Green (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25301289&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mrg@...&lt;/a&gt;) if he
&lt;br&gt;would like to be on the core team, and Matt has kindly accepted. &amp;nbsp;Matt
&lt;br&gt;is well-known throughout the NetBSD community, and has been an active
&lt;br&gt;developer longer than most developers. &amp;nbsp;Most recently, Matt has been
&lt;br&gt;the driving force behind X11 in the base system, and related DRM work.
&lt;br&gt;In the past, Matt has worked on compilers and binutils, but may be
&lt;br&gt;most widely known for his gzip frontend to zlib, and his work on our
&lt;br&gt;pax utility. Some others may automatically associate him with bozohttpd,
&lt;br&gt;as he is the author of that, or with ircII, which Matt maintains. It may
&lt;br&gt;be quicker to just list the areas of the tree which he hasn't written.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Welcome, Matt!
&lt;br&gt;&amp;nbsp;
&lt;br&gt;The Board of Directors of The NetBSD Foundation would like to announce
&lt;br&gt;that the new NetBSD core team will consist of:
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Alistair Crooks (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25301289&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;agc@...&lt;/a&gt;)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Matt Green (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25301289&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mrg@...&lt;/a&gt;)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Yamamoto Takashi (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25301289&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;yamt@...&lt;/a&gt;)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Matt Thomas (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25301289&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;matt@...&lt;/a&gt;)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Christos Zoulas (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25301289&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;christos@...&lt;/a&gt;)
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Alistair Crooks
&lt;br&gt;on behalf of the Board of Directors
&lt;br&gt;The NetBSD Foundation
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Core-Team-Changes-tp25301289p25301289.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24844270</id>
	<title>Planned network outage for netbsd.org servers Sat Aug 8th 16:00 UTC ff</title>
	<published>2009-08-06T00:21:23Z</published>
	<updated>2009-08-06T00:21:23Z</updated>
	<author>
		<name>spz</name>
	</author>
	<content type="html">Dear all,
&lt;br&gt;&lt;br&gt;ISC is planning work on a pretty central router that will affect
&lt;br&gt;the NetBSD.org servers hosted at ISC (mail, www, ftp, anoncvs, blog etc).
&lt;br&gt;&lt;br&gt;This maintenance is supposed to start around 16:00 UTC on Sat Aug 8th,
&lt;br&gt;and will take a few hours. Connectivity will likely not be down the
&lt;br&gt;entire time, but don't expect it to be stable or plentiful.
&lt;br&gt;Please use mirrors where available.
&lt;br&gt;&lt;br&gt;regards,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; spz
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Planned-network-outage-for-netbsd.org-servers-Sat-Aug-8th-16%3A00-UTC-ff-tp24844270p24844270.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24781989</id>
	<title>Announcing NetBSD 5.0.1</title>
	<published>2009-08-02T13:48:30Z</published>
	<updated>2009-08-02T13:48:30Z</updated>
	<author>
		<name>snj</name>
	</author>
	<content type="html">On behalf of the NetBSD developers, I am pleased to announce that
&lt;br&gt;NetBSD 5.0.1 is now available for download. &amp;nbsp;NetBSD 5.0.1 is the first
&lt;br&gt;security/critical update of the NetBSD 5.0 release branch. It represents
&lt;br&gt;a selected subset of fixes deemed critical in nature for security or
&lt;br&gt;stability reasons. &amp;nbsp;All users are encouraged to upgrade.
&lt;br&gt;&lt;br&gt;Please note that due to changes in pkg_install, users upgrading from
&lt;br&gt;previous releases are strongly encouraged to run &amp;quot;pkg_admin rebuild&amp;quot;
&lt;br&gt;after the upgrade is complete.
&lt;br&gt;&lt;br&gt;For full details, please see the release notes at:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.NetBSD.org/releases/formal-5/NetBSD-5.0.1.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/releases/formal-5/NetBSD-5.0.1.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;ISO images can be downloaded using BitTorrent, and we encourage users
&lt;br&gt;who wish to install via ISO images to take advantage of this, as the
&lt;br&gt;images are well seeded.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.NetBSD.org/mirrors/torrents/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/mirrors/torrents/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Complete source and binaries for NetBSD 5.0.1 are available for download
&lt;br&gt;at many sites around the world. A list of download sites providing FTP,
&lt;br&gt;AnonCVS, and other services may be found at:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.NetBSD.org/mirrors/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/mirrors/&lt;/a&gt;&lt;br&gt;&lt;br&gt;We are very grateful to all of those who donated during the 2007 fund
&lt;br&gt;drive, which brought us many of the great advances made in the last two
&lt;br&gt;years. &amp;nbsp;We would like to remind everyone that we are in the middle of
&lt;br&gt;a fund drive with a target of 60,000 USD by the end of the year. &amp;nbsp;For
&lt;br&gt;more information on how you can help NetBSD reach this goal, see
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.NetBSD.org/donations/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/donations/&lt;/a&gt;&lt;br&gt;&lt;br&gt;The NetBSD Foundation would like to thank all those who have
&lt;br&gt;contributed code, hardware, documentation, funds, colocation for our
&lt;br&gt;servers, web pages and other documentation, release engineering, and
&lt;br&gt;other resources over the years. More information on the people who
&lt;br&gt;make NetBSD happen is available at:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.NetBSD.org/people/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/people/&lt;/a&gt;&lt;br&gt;&lt;br&gt;We would like to especially thank the University of California at
&lt;br&gt;Berkeley and the GNU Project for particularly large subsets of code
&lt;br&gt;that we use. We would also like to thank the Internet Systems
&lt;br&gt;Consortium Inc., the Network Security Lab at Columbia University's
&lt;br&gt;Computer Science Department, and Ludd (Luleaa Academic Computer
&lt;br&gt;Society) computer society at Luleaa University of Technology for
&lt;br&gt;current colocation services.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Announcing-NetBSD-5.0.1-tp24781989p24781989.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24716957</id>
	<title>NetBSD Security Advisory 2009-013: BIND named dynamic update Denial of Service vulnerability</title>
	<published>2009-07-29T00:30:07Z</published>
	<updated>2009-07-29T00:30:07Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-013
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		BIND named dynamic update Denial of Service vulnerability
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:		affected prior to 2009-07-29
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.*:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc:			bind package prior to 9.5.1pl3 and 9.6.1pl1
&lt;br&gt;&lt;br&gt;Severity:	Denial of Service
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current:		July 28, 2009 21:13 UTC
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5-0 branch:	July 28, 2009 22:26 UTC
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5 branch:	July 28, 2009 22:26 UTC
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4-0 branch:	July 28, 2009 22:19 UTC
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4 branch:	July 28, 2009 22:19 UTC
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc 2009Q2:		bind-9.5.1pl3 and bind-9.6.1pl1 corrects this issue
&lt;br&gt;&lt;br&gt;Please note that NetBSD releases prior to 4.0 are no longer supported.
&lt;br&gt;It is recommended that all users upgrade to a supported release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;An assertion failure in the Berkeley Internet Name Domain server
&lt;br&gt;software shipped in NetBSD can be used by a remote attacker to
&lt;br&gt;cause the server process to crash by sending specially crafted
&lt;br&gt;dynamic update messages.
&lt;br&gt;&lt;br&gt;This vulnerability has been assigned CVE-2009-0696 and CERT
&lt;br&gt;Vulnerability Note VU#725188.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;An error handling dynamic DNS update packets with the record data
&lt;br&gt;type being set to &amp;quot;ANY&amp;quot; will cause an assertion in the
&lt;br&gt;dns_db_findrdataset() function to trigger, causing the name server
&lt;br&gt;to exit. This requires at least one of the record set entries
&lt;br&gt;specified in the update to exist on the local server.
&lt;br&gt;&lt;br&gt;The assertion triggered will typically cause the following message:
&lt;br&gt;&lt;br&gt;&amp;nbsp; db.c:659: REQUIRE(type != ((dns_rdatatype_t)dns_rdatatype_any)) failed
&lt;br&gt;&amp;nbsp; exiting (due to assertion failure). 
&lt;br&gt;&lt;br&gt;Note that this assertion will be triggered even if dynamic DNS
&lt;br&gt;updates are disabled.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;In order to avoid this vulnerability, either filter incoming dynamic
&lt;br&gt;DNS update requests using a firewall or upgrade your bind software
&lt;br&gt;to a non-vulnerable version.
&lt;br&gt;&lt;br&gt;The following instructions describe how to upgrade your bind binaries
&lt;br&gt;by updating your source tree and rebuilding and installing a new
&lt;br&gt;version of bind.
&lt;br&gt;&lt;br&gt;* NetBSD-current:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD-current dated from before 2009-07-28
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 21:13 UTC should be upgraded to NetBSD-current dated
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-28 21:13 UTC or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-current CVS branch (aka HEAD):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; external/bsd/bind/dist
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install bind:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P external/bsd/bind/dist
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd external/bsd/bind/bin/named
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;* NetBSD 5.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 5.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-28 22:26 UTC should be upgraded from NetBSD 5.*
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sources dated 2009-07-28 22:26 UTC or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-5 or netbsd-5-0 branches:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/bind/bin/named/update.c
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install bind:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P dist/bind/bin/named/update.c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/bind/named
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;* NetBSD 4.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 4.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-28 22:19 UTC should be upgraded from NetBSD 4.* sources
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dated 2009-07-28 22:19 UTC or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-4 or netbsd-4-0 branches:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/bind/bin/named/update.c
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install bind:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P dist/bind/bin/named/update.c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/bind/named
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;Matthias Urlichs for finding and reporting this bug and Christos Zoulas
&lt;br&gt;for fixing it in NetBSD.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-29	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at 
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-013.txt.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-013.txt.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-013.txt,v 1.1 2009/07/29 06:54:37 tonnerre Exp $
&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQIcBAEBAgAGBQJKb/JnAAoJEAZJc6xMSnBu9+UP+gJmgL1T1NkLAkecNDH/i5ST
&lt;br&gt;sHSY3ifMoEDaMnEIYe+h/LtdiQx6BFOhUbtVuT8trInjjvSmwfw0j/gF7WnHoKxO
&lt;br&gt;9BgR4Z0BoTL2N+g5+opZHnn/m3JI7Q3X7oVw3YSAVT3OzAhSANT8bijhs/XlvCIu
&lt;br&gt;A1B6gjxfRb1A5oiD94qlBT072WLakDj9C42kTqyt1H5Bf5zLbD7V6E9HZVW6kRI4
&lt;br&gt;YiYDTTXgOrHpRxKprFYszn7r0bb8JeJeDnMq7M/u2ZcnNGjz3VB9PXU7Qbotytc2
&lt;br&gt;Or2bDpGanpnn0/9ARS+GAEfmVR7v8bG7Q32IUyV+o1RbGcdH4Z66d9nnopjrC6Fp
&lt;br&gt;OfAzQHR00QOgMibuvuvV1bzIgsDoJ7lZ97ptFHEZM+nMx4j6p/exCowZIlLv1OGD
&lt;br&gt;myREoE2tHxstvQpXBd7mszcYBdr+9BzE6tRSY/TtzFHj4uMzt2/nOo8iCq7ac6U1
&lt;br&gt;XXLzTmAMG7+sRHgEpv9TAn2of0azUXkwGYhNX8ibJyQXdalVowpCti99+bzJjUSF
&lt;br&gt;OTPOT0CGrAU0URnYZfsF+03Uj0REccmRqR5WZBpegmSBy8AoUtG0BjREABDifB3m
&lt;br&gt;PDi12xUawr8xdbNHTTTfiKzyAXbmfcg4NrTqw3o1OvtIVueNu6+56apMZyk7oUAY
&lt;br&gt;OZwSsME+s8EkcORvH8ks
&lt;br&gt;=05bL
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-013%3A-BIND-named-dynamic-update-Denial-of-Service-vulnerability-tp24716957p24716957.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24708666</id>
	<title>NetBSD Security Advisory 2009-012: SHA2 implementation potential buffer overflow</title>
	<published>2009-07-28T14:52:35Z</published>
	<updated>2009-07-28T14:52:35Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-012
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		SHA2 implementation potential buffer overflow
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:		affected prior to 2009-05-26
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.*:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:		affected
&lt;br&gt;&lt;br&gt;Severity:	Denial of Service
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current:		May 26, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5-0 branch:	Jul 11, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5 branch:	Jul 11, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4-0 branch:	Jul 22, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4 branch:	Jul 22, 2009
&lt;br&gt;&lt;br&gt;Please note that NetBSD releases prior to 4.0 are no longer supported.
&lt;br&gt;It is recommended that all users upgrade to a supported release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;An error initializing a SHA2 context causes vulnerable applications using
&lt;br&gt;libcrypto to suffer from a 4- or 8-byte buffer overflow (for SHA256 and
&lt;br&gt;SHA512 correspondingly) with fixed content, potentially causing
&lt;br&gt;applications to crash.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;A program using the SHA2 implementation from sys/sha2.h in NetBSD and
&lt;br&gt;linking against libcrypto is vulnerable to a 4- or 8-byte buffer
&lt;br&gt;overflow (for SHA256 and SHA512 correspondingly) with fixed content.
&lt;br&gt;&lt;br&gt;The overflow occurs at the time the hash init function is called (e.g.
&lt;br&gt;SHA256_Init). The init functions then pass the wrong size for the
&lt;br&gt;context as an argument to the memset function which then overwrites
&lt;br&gt;4 bytes of the memory buffer located after the one holding the context.
&lt;br&gt;&lt;br&gt;In the NetBSD base system, this affects the libssh library as well as
&lt;br&gt;the pkg_install framework. In libssh, the overflow occurs on the heap
&lt;br&gt;of the program using it, in pkg_install a stack overflow occurs.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;A workaround for this issue for programs in the NetBSD base system
&lt;br&gt;is to disable SHA256 as a HMAC for the secure shell and to avoid
&lt;br&gt;using the audit facility as well as signed packages.
&lt;br&gt;&lt;br&gt;To determine whether or not a package is signed, run the command
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; % tar tzf package.tgz
&lt;br&gt;&lt;br&gt;on the package. If the first file of the package is +PKG_HASH,
&lt;br&gt;then the package is signed.
&lt;br&gt;&lt;br&gt;The following instructions describe how to upgrade your libcrypto
&lt;br&gt;and libc binaries by updating your source tree and rebuilding and
&lt;br&gt;installing a new version of the three facilities.
&lt;br&gt;&lt;br&gt;* NetBSD-current:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD-current dated from before 2009-05-26
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; should be upgraded to NetBSD-current dated 2009-05-27 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-current CVS branch (aka HEAD):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; common/lib/libc/hash/sha2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; distrib/sets/lists
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lib/libc
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lib/libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sys/sys
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install lorem:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P common/lib/libc/hash/sha2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P distrib/sets/lists
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P lib/libc
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P lib/libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P sys/sys
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd sys/sys
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../lib/libc
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypt
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;* NetBSD 5.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 5.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-11 should be upgraded from NetBSD 5.* sources dated
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-12 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-5 or netbsd-5-0 branches:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; common/lib/libc/hash/sha2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; distrib/sets/lists
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lib/libc
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lib/libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sys/sys
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install libc and libcrypto:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P common/lib/libc/hash/sha2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P distrib/sets/lists
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P lib/libc
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P lib/libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P sys/sys
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd sys/sys
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../lib/libc
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypt
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;* NetBSD 4.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 4.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-22 should be upgraded from NetBSD 4.* sources dated
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-23 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-4 or netbsd-4-0 branches:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; common/lib/libc/hash/sha2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; distrib/sets/lists
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lib/libc
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lib/libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sys/sys
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install libc and libcrypto:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P common/lib/libc/hash/sha2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P distrib/sets/lists
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P lib/libc
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P lib/libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P sys/sys
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd sys/sys
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../lib/libc
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypt
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;Joerg Sonnenberger for finding, reporting and fixing the issue.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-28	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at 
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-012.txt.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-012.txt.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-012.txt,v 1.1 2009/07/28 18:29:29 tonnerre Exp $
&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQIcBAEBAgAGBQJKb0ijAAoJEAZJc6xMSnBuBEEP+wa1ybcKmHkq16evmfBdGIpM
&lt;br&gt;9Z7fVSvx5fDHMvUDGKL5tST/CIoRU379yiBIj/VS0tlUV9TLo1TPdrLO9XON0ara
&lt;br&gt;CaIP3DK766+hjya0PwuVuy8yVhUQ6Dz2rKTBjSpmz38qv8RfvR4G6iwF3W6YNvNu
&lt;br&gt;pF3vjEJIbQdT6Fen3pzb4D9aiQ6SvEZdknGGR2HmebY2ig4un+bsIJc3x+Iv87Iw
&lt;br&gt;qpuJ6KQSnfLxx5qFVO5Sax8SNdL3VmQQcFhVgO3tg/ddcFUVwngXS2Wg9ChczQWt
&lt;br&gt;7wM7OVwXOL1Vr0s2NcRlsIppHXvKRQxu54CuEQM6gsPcleJhsBVFo9/AbeSw4SAx
&lt;br&gt;rLiR/jQ6vsC9/28ZpKGQkrtnf5fxP2R7uQIN2nylCiB+s5UDmAHAYTt1tSTMt4ou
&lt;br&gt;+xgCX0OnE9iB68FoJYq1YjHMc3n4GclJz3lijXsRBzgGaSHZJc3ywYtO6puS8yUI
&lt;br&gt;mXKWPdGthCDVXWiKUOBZYcuS4dv7RoA+VhI3Q1P/kwFQ9xXqb9XWSQYmLycxleA8
&lt;br&gt;BjjSEuIlw5tdAnufDJA8ZRXl4gP0qhrKfPtyYkLUj6pezcyPU1QD61yK0euMr3sq
&lt;br&gt;lO97lYhYqtc2gMJaOgVYoHUqbsemuRNEOdHMBeqIoC8MYYH5La6Tuub26Dwz7eDV
&lt;br&gt;Mxw6htX0zEm1S/1ld7ne
&lt;br&gt;=GZuc
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-012%3A-SHA2-implementation-potential-buffer-overflow-tp24708666p24708666.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24708604</id>
	<title>NetBSD Security Advisory 2009-011: ISC DHCP server Denial of Service vulnerability</title>
	<published>2009-07-28T14:51:56Z</published>
	<updated>2009-07-28T14:51:56Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-011
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		ISC DHCP server Denial of Service vulnerability
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:		affected prior to 2009-07-16
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.*:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc:			isc-dhcpd package prior to 3.1.1p1
&lt;br&gt;&lt;br&gt;Severity:	Denial of Service
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current:		Jul 16, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5-0 branch:	Jul 17, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5 branch:	Jul 17, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4-0 branch:	Jul 17, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4 branch:	Jul 17, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc 2009Q2:		isc-dhcpd-3.1.1p1 corrects this issue
&lt;br&gt;&lt;br&gt;Please note that NetBSD releases prior to 4.0 are no longer supported.
&lt;br&gt;It is recommended that all users upgrade to a supported release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;A reference counting error in dhcpd allows a remote attacker to cause
&lt;br&gt;a daemon crash by submitting requests with the same client ID on
&lt;br&gt;different interfaces served by the same daemon.
&lt;br&gt;&lt;br&gt;This vulnerability has been assigned CVE-2009-1892.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;A reference counting error in dhcpd allows a remote attacker to cause
&lt;br&gt;a daemon crash by submitting requests with the same client ID on
&lt;br&gt;different interfaces served by the same daemon.
&lt;br&gt;&lt;br&gt;This requires that client ID based configurations are mixed in the
&lt;br&gt;configuration file with hardware address based configurations.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;In order to fix the vulnerability on your local machine, either
&lt;br&gt;make sure that only client-id based statements or hardware ethernet
&lt;br&gt;statements are used, or upgrade to a non-vulnerable version of
&lt;br&gt;dhcpd.
&lt;br&gt;&lt;br&gt;The following instructions describe how to upgrade your dhcpd
&lt;br&gt;binaries by updating your source tree and rebuilding and
&lt;br&gt;installing a new version of dhcpd.
&lt;br&gt;&lt;br&gt;* NetBSD-current:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD-current dated from before 2009-07-16
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; should be upgraded to NetBSD-current dated 2009-07-17 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-current CVS branch (aka HEAD):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/dhcp/server
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install lorem:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P dist/dhcp/server
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/dhcp
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd server
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;* NetBSD 5.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 5.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-17 should be upgraded from NetBSD 5.* sources dated
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-18 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-5 or netbsd-5-0 branches:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/dhcp/server
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install dhcpd:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P dist/dhcp/server
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/dhcp
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd server
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;* NetBSD 4.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 4.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-17 should be upgraded from NetBSD 4.* sources dated
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-18 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-4 or netbsd-4-0 branches:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/dhcp/server
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install dhcpd:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P dist/dhcp/server
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/dhcp
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd server
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;Christoph Biedl for discovering and reporting the issue, and Florian
&lt;br&gt;Weimer for the fix.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-28	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at 
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-011.txt.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-011.txt.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-011.txt,v 1.1 2009/07/28 18:29:29 tonnerre Exp $
&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQIcBAEBAgAGBQJKb0iQAAoJEAZJc6xMSnBujKAP/14r5KM5VfyEfsLgrId7XiKY
&lt;br&gt;Ms28lQ5i7gUI+0hfNPh7QbADIGCim0Gdn3XVybgVNWZcFWNOQWwQfRu+/2Zv9JeG
&lt;br&gt;SLBUp+xJ7eqWxM66oZYvPK4csB18L/qZSWouHdDxA1z64+S8Qsn9pz6Y1hih/eoh
&lt;br&gt;b1WWa9ZcE/7JxYINVCH4RKQIn7TRPWqLex1MWf3jGJafAH3XRpgfCWUbgkTB4CTU
&lt;br&gt;xNahopXzt3Xpdmd8j9kRPzLnP7UEUOwQapcQAJ88tlMISNh5zbRuuxWHJGDwxM3l
&lt;br&gt;pBm65TvItT2N+D2Z/4CkduK8Z1U7nM0pXR/amJOrrotK0kllLMhH+sYZ5lROLx8R
&lt;br&gt;DFHuaDYxPQ0xOySVRc3rnPguatm27TB/BgSiFC/vEU030OXB90dboTDsnQhRn0WI
&lt;br&gt;5jAfC1iKzq/fN6rMsKKaZ718En5lLV8Qcew29IGJUMS8vC5+PZ3yDHOSVXZiFjp0
&lt;br&gt;r8RZj1EucuzJKYT5veqZ2SSSK14elvczclpyBir+GyhEuh9RLS71k/Td9DlsPrMR
&lt;br&gt;XhE3V3/ygyQcBZJ69xn0QGlXHInMPc1aRNDxObg+511i8ugvpb6V71VFQOeF81/7
&lt;br&gt;M7qqAl2W3ojMzHTISXUHRSICB3dyJ8jy9y9GFRpw6UkvUyskuGttYYhA85EuPexi
&lt;br&gt;WVkLaq9xsgfSYqB9+71X
&lt;br&gt;=PW6s
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-011%3A-ISC-DHCP-server-Denial-of-Service-vulnerability-tp24708604p24708604.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24630349</id>
	<title>More brief outages of ftp.netbsd.org TODAY, 2009-07-23</title>
	<published>2009-07-23T10:08:48Z</published>
	<updated>2009-07-23T10:08:48Z</updated>
	<author>
		<name>Thor Lancelot Simon-3</name>
	</author>
	<content type="html">At or after 18:00UTC today, July 23, 2009, there will be one or more
&lt;br&gt;brief outages of ftp.netbsd.org as we prepare to rearrange services
&lt;br&gt;using new and upgraded hardware.
&lt;br&gt;&lt;br&gt;Thor
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/More-brief-outages-of-ftp.netbsd.org-TODAY%2C-2009-07-23-tp24630349p24630349.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24488763</id>
	<title>NetBSD Security Advisory 2009-005: Plaintext Recovery Attack Against SSH</title>
	<published>2009-07-14T14:33:52Z</published>
	<updated>2009-07-14T14:33:52Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-005
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		Plaintext Recovery Attack Against SSH
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:	source prior to June 8, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:	source prior to June 30, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.1:	source prior to June 30, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:	source prior to June 30, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc:		openssh packages prior to 5.2
&lt;br&gt;&lt;br&gt;Severity:	Information leakage from SSH sessions
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current: &amp;nbsp; &amp;nbsp;June 8, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5 branch: &amp;nbsp; June 30, 2009 (5.0.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4 branch: &amp;nbsp; June 30, 2009 (4.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4-0 branch: June 30, 2009 (4.0.2 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc 2009Q1:	 &amp;nbsp; openssh-5.2 corrects this issue
&lt;br&gt;&lt;br&gt;Please note that NetBSD releases prior to 4.0 are no longer supported.
&lt;br&gt;It is recommended that all users upgrade to a supported release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;A defect exists in SSH protocol that allows active attackers to
&lt;br&gt;recover plaintext from an SSH session if a CBC mode cipher is in
&lt;br&gt;use. Updated versions of OpenSSH mitigate this problem.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/32760/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/32760/&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.cpni.gov.uk/Docs/Vulnerability_Advisory_SSH.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cpni.gov.uk/Docs/Vulnerability_Advisory_SSH.txt&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.kb.cert.org/vuls/id/958563&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.kb.cert.org/vuls/id/958563&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;The CBC cipher mode of the SSH protocol allows a remote attacker
&lt;br&gt;to recover up to 32 bits of plaintext data from an existing SSH
&lt;br&gt;session by sending specially crafted packets. This can be mitigated
&lt;br&gt;either through changes of the sshd_config and ssh_config files or
&lt;br&gt;by updating to the latest version of OpenSSH.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://secunia.com/advisories/32760/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://secunia.com/advisories/32760/&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.cpni.gov.uk/Docs/Vulnerability_Advisory_SSH.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cpni.gov.uk/Docs/Vulnerability_Advisory_SSH.txt&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.kb.cert.org/vuls/id/958563&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.kb.cert.org/vuls/id/958563&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;&lt;br&gt;The problem can be mitigated by disabling the CBC mode ciphers
&lt;br&gt;using the following directive in sshd_config and ssh_config:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; Ciphers aes128-ctr,aes256-ctr,arcfour256,arcfour,aes128-cbc,aes256-cbc
&lt;br&gt;&lt;br&gt;This makes the CBC ciphers most unlikely to be selected, reducing
&lt;br&gt;the likelyhood of exposure.
&lt;br&gt;&lt;br&gt;In order to fix the underlying problem, users should upgrade their
&lt;br&gt;SSH clients and servers. The information leak vulnerability requires
&lt;br&gt;an active attack and is not easy to exploit, but is potentially
&lt;br&gt;dangerous.
&lt;br&gt;&lt;br&gt;The following instructions describe how to upgrade your SSH
&lt;br&gt;binaries by updating your source tree and rebuilding and
&lt;br&gt;installing a new version of SSH.
&lt;br&gt;&lt;br&gt;* NetBSD-current:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD-current dated from before 2009-06-08
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; should be upgraded to NetBSD-current dated 2009-06-09 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-current CVS branch (aka HEAD):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; crypto/external/bsd/openssh/dist
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install SSH:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P crypto/external/bsd/openssh/dist
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.bin/ssh
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;* NetBSD 5.0:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The binary distribution of NetBSD 5.0 is vulnerable.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 5.0 sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-29 23:00 UTC should be upgraded from NetBSD 5.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sources dated 2009-06-30 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0.1 and 5.1 will include the fix.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-5-0 CVS branch:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; crypto/dist/ssh
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install SSH:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P -r netbsd-5-0 crypto/dist/ssh
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.bin/ssh
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Alternatively, apply the following patch (with potential offset
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; differences):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ftp://ftp.NetBSD.org/pub/NetBSD/security/patches/SA2009-005-openssh-nb5.patch
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To patch, re-build and re-install SSH:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src/crypto/dist/ssh
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # patch &amp;lt; /path/to/SA2009-005-openssh-nb5.patch
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../../usr.bin/ssh
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make install
&lt;br&gt;&lt;br&gt;&lt;br&gt;* NetBSD 4.0, 4.0.1:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The binary distributions of NetBSD 4.0 and 4.0.1 are vulnerable.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 4.0 sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-30 01:00 UTC should be upgraded from NetBSD 4.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sources dated 2009-06-30 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.1 and 4.0.2 will include the fix.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-4-0 CVS branch:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; crypto/dist/ssh
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install SSH:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P -r netbsd-4-0 crypto/dist/ssh
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.bin/ssh
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Alternatively, apply the following patch (with potential offset
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; differences):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ftp://ftp.NetBSD.org/pub/NetBSD/security/patches/SA2009-005-openssh-nb4.patch
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To patch, re-build and re-install SSH:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src/dist/ssh
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # patch &amp;lt; /path/to/SA2009-005-openssh-nb4.patch
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../../usr.bin/ssh
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make install
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;Martin Albrecht, Kenny Paterson and Gaven Watson from the
&lt;br&gt;Information Security Group at Royal Holloway, University of
&lt;br&gt;London for finding and reporting the issue.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-30	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at 
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-005.txt.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-005.txt.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-005.txt,v 1.1 2009/06/30 00:32:25 tonnerre Exp $
&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQIcBAEBAgAGBQJKSl6UAAoJEAZJc6xMSnBuspkQALQuPHnJla8/j0MF5jvPZJoy
&lt;br&gt;7+Y9XbmLOMux/c80lqGINX4aRCj+H9JZ8IWkIU7iTnKri6tn4AurhfE6LI4Mta84
&lt;br&gt;OQ/VFz5t8QCYfuhuBZeAUnW6CLShnwdVBoLBitpAeQEavTHTiyz3BMEQpXFlWsya
&lt;br&gt;VtFsiKF8GnkcQNI3f6/iNCwMSrloiMiTTCaovG0Kt0iITBAl5kO4EKf1y2us/KcI
&lt;br&gt;KpPd7rKR0hdyK1hPt/ZRh0s981rwm+/ZjIzPfjgEj9cSWHn0mCbAqycqrqdEjeOK
&lt;br&gt;i3UW0JtRjE/EFcFKJLOTA86mlU9oTK1J5Z4mk/o/AB/3BVtntRLgv56VLE72aYBc
&lt;br&gt;ZPbEGMIGAmwhKk67u+jwdGtOE+C8Dge3F+GWzLy51fW7kHPmDlKpiKSmg1Qo0SdB
&lt;br&gt;8qwiCwuDWOvqaGeIMaKqgM2wrQxlY+bjz4eiYBrDPH+bazcQfrwXRGRXlEDhWi43
&lt;br&gt;pEd7XbCKz0KJSx16ZxRqXDeVvjtAEGucfDeakMYzAFjq832RlE+jAoJ3z69sDALZ
&lt;br&gt;goRqvSO//VrOaAuIaUJwE8A4SraJWD3tCzGxk2niZW2ZYwMYoJnaIO0fHbsZ45yN
&lt;br&gt;G5SzqPTUKtjKX5d3swdnNbPVaXi5jUKZtggzfyu286r9gziSUN2yqhEXQYcTzvK1
&lt;br&gt;/ujYOT/k3khhYjG9CbVh
&lt;br&gt;=rKrv
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-005%3A-Plaintext-Recovery-Attack-Against-SSH-tp24488763p24488763.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24488793</id>
	<title>NetBSD Security Advisory 2009-010: ISC dhclient subnet-mask flag stack overflow</title>
	<published>2009-07-14T14:31:46Z</published>
	<updated>2009-07-14T14:31:46Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-010
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		ISC dhclient subnet-mask flag stack overflow
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:		affected before June 24, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.*:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc:			isc-dhclient package prior to
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 4.1.0p1, 4.0.1p1, or 3.1.2p1
&lt;br&gt;&lt;br&gt;Severity:	Arbitrary Code Execution
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current:		June 24, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5-0 branch:	July 14, 2009 20:00 UTC
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5 branch:	July 14, 2009 20:00 UTC
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4-0 branch:	July 14, 2009 20:00 UTC
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4 branch:	July 14, 2009 20:00 UTC
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc 2009Q2:		isc-dhclient-4.1.0p1, 4.0.1p1 and
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 3.1.2p1 correct the issue
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;A stack overflow vulnerability in ISC dhclient allows an attacker
&lt;br&gt;operating a rogue DHCP server to execute arbitrary code with root
&lt;br&gt;privileges on the affected system by supplying a specially crafted
&lt;br&gt;subnet-mask parameter.
&lt;br&gt;&lt;br&gt;This vulnerability has been assigned CVE-2009-0692 and CERT
&lt;br&gt;Vulnerability Note VU#410676.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;The script_write_params() function in ISC dhclient version 4.1.0 and
&lt;br&gt;earlier, 4.0.1 and earlier as well as 3.1.2 and earlier fails to
&lt;br&gt;properly verify the subnet-mask parameter while copying it into
&lt;br&gt;the internal state.
&lt;br&gt;&lt;br&gt;This can be exploited to overwrite the stack frame pointer and execute
&lt;br&gt;arbitrary code in the context of the dhclient process. The size of the
&lt;br&gt;injected code is thereby limited to the MTU of the interface dhclient
&lt;br&gt;is listening on.
&lt;br&gt;&lt;br&gt;For more details, please see CVE-2009-0692.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;As a temporary workaround, disable dhclient(8) from the base OS and
&lt;br&gt;use either the fixed dhclient packages from pkgsrc, or alternatively
&lt;br&gt;the program dhcpcd(8) from the base system.
&lt;br&gt;&lt;br&gt;The following instructions describe how to upgrade your dhclient
&lt;br&gt;binaries by updating your source tree and rebuilding and
&lt;br&gt;installing a new version of dhclient.
&lt;br&gt;&lt;br&gt;* NetBSD-current:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD-current dated from before 2009-06-24
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; should be upgraded to NetBSD-current dated 2009-06-25 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following file needs to be updated from the netbsd-current
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; CVS branch (aka HEAD):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/dhcp/client/dhclient.c
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install dhclient:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P dist/dhcp/client/dhclient.c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/dhcp
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd client
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;* NetBSD 5.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 5.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-14 20:00 UTC should be upgraded from NetBSD 5.*
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sources dated 2009-07-14 20:00 UTC or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following file needs to be updated from the netbsd-5 or
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-5-0 branches:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/dhcp/client/dhclient.c
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install dhclient:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P dist/dhcp/client/dhclient.c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/dhcp
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd client
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Alternatively, apply the following patch (with potential offset
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; differences):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://ftp.NetBSD.org/pub/NetBSD/security/patches/SA2009-010-dhclient.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.NetBSD.org/pub/NetBSD/security/patches/SA2009-010-dhclient.patch&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To patch, re-build and re-install SSH:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd dist/dhcp/client
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # patch -p0 &amp;lt; /path/to/SA2009-010-dhclient.patch
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../../usr.sbin/dhcp
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd client
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;* NetBSD 4.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 4.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-14 20:00 UTC should be upgraded from NetBSD 4.*
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; sources dated 2009-07-14 20:00 UTC or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following file needs to be updated from the netbsd-4 or
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-4-0 branches:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/dhcp/client/dhclient.c
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install dhclient:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P dist/dhcp/client/dhclient.c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/dhcp
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd client
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Alternatively, apply the following patch (with potential offset
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; differences):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://ftp.NetBSD.org/pub/NetBSD/security/patches/SA2009-010-dhclient.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.NetBSD.org/pub/NetBSD/security/patches/SA2009-010-dhclient.patch&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To patch, re-build and re-install SSH:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd dist/dhcp/client
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # patch -p0 &amp;lt; /path/to/SA2009-010-dhclient.patch
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../../usr.sbin/dhcp
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd client
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;The Mandriva Linux Engineering Team and for discovering and reporting
&lt;br&gt;the software flaw and Christos Zoulas for providing a fix.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-14	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at 
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-010.txt.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-010.txt.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-010.txt,v 1.2 2009/07/14 20:40:33 tonnerre Exp $
&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQIcBAEBAgAGBQJKXO1UAAoJEAZJc6xMSnBudBkQAJPPZ55nwsFZOp5V8tOIhuki
&lt;br&gt;a+YKDE5zaa9AvIrvpzZqUIE9F9/FR92Ke7Sh5Ol7zxpnBJXwsEYIJfdKBW47Bx8y
&lt;br&gt;drZ7KPvOyga8dqDE8OQWRzCWfpbzYGSIp706TlO0ONBzZLUN4JCy60kbZtAwXt83
&lt;br&gt;oM50DTA9DhtIxy+MOJyStnHArZLQZYH4VTNBdQb3UmJR+/LjQIY2oxvLBwN/QKOB
&lt;br&gt;mfFfyxHwgZXkY9dUXSB+wsdEtgLOToVUhDsrcNvzYYH9Dxs2unBpXdTFCy4BYcAZ
&lt;br&gt;o5FiSEW5lHReDCiql5PZ+6AfiehzabmPC3rZLTD9QgjE3cPlrVA7XZsmnZnsxAF1
&lt;br&gt;4O1/w8Pz4pl+X+84+JsbQCSkhMRX4zlkZ2lUtTtF9FZ73wHPih3oK1MN8ssW414c
&lt;br&gt;Pms36xxKgmop/xw58/SGtlmaFD+0sUm6fSZBAlD5BDuSwqvWVUIvHXxEoAuN2Vbc
&lt;br&gt;j65njdgvrpZ5VG0bX4CxE1rbxhjCJ0wwRgU3MgH36Pv6bFV3TBWqriGHIr9VmDbt
&lt;br&gt;qGyQJdLlejW4cUjVhz8ZProbWhsvpoObtuAetysyhwRke6Ie/ssvon+0iLz4QikO
&lt;br&gt;Nh2eaVdqQqJZRFOPGyxPoYjT1KU27+C7Xos+2D+VT/rnk/lnKcOG1ye+v0B7HNgc
&lt;br&gt;eNYsWmC3rp8NPDDc6N18
&lt;br&gt;=Jf/4
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-010%3A-ISC-dhclient-subnet-mask-flag-stack-overflow-tp24488793p24488793.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24472196</id>
	<title>Brief outage of ftp.netbsd.org TODAY, 2009-07-14 02:45 UTC</title>
	<published>2009-07-13T17:35:58Z</published>
	<updated>2009-07-13T17:35:58Z</updated>
	<author>
		<name>Thor Lancelot Simon-3</name>
	</author>
	<content type="html">At or around 02:45:00 UTC today, ftp.netbsd.org will be unavailable for
&lt;br&gt;a brief interval expected to be less than two hours, for a CPU and memory
&lt;br&gt;upgrade. &amp;nbsp;This is the first step of a major round of upgrades planned for
&lt;br&gt;the NetBSD Foundation servers, and should provide better performance and
&lt;br&gt;more reliable service for our users.
&lt;br&gt;&lt;br&gt;Apologies for the short notice. &amp;nbsp;We hope the outage will actually be so
&lt;br&gt;short it will be invisible to most of the users of ftp.netbsd.org.
&lt;br&gt;&lt;br&gt;Thor
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Brief-outage-of-ftp.netbsd.org-TODAY%2C-2009-07-14-02%3A45-UTC-tp24472196p24472196.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24390494</id>
	<title>NetBSD Security Advisory 2009-009: OpenSSL DTLS Memory Exhaustion and DSA signature verification vulnerabilities</title>
	<published>2009-07-07T21:46:03Z</published>
	<updated>2009-07-07T21:46:03Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		OpenSSL DTLS Memory Exhaustion and DSA signature
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; verification vulnerabilities
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:		affected prior to 2009-07-04
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.*:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc:			openssl package prior to 0.9.8j
&lt;br&gt;&lt;br&gt;Severity:	Denial of Service, DSA signature spoofing
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current:		July 4, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5-0 branch:	July 4, 2009 (NetBSD 5.0.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5 branch:	July 4, 2009 (NetBSD 5.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4-0 branch:	July 4, 2009 (NetBSD 4.0.2 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4 branch:	July 4, 2009 (NetBSD 4.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc 2009Q1:		openssl-0.9.8j corrects this issue
&lt;br&gt;&lt;br&gt;Please note that NetBSD releases prior to 4.0 are no longer supported.
&lt;br&gt;It is recommended that all users upgrade to a supported release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;Two range check errors in the DTLS code allow a remote attacker
&lt;br&gt;to exhaust memory by executing too many out of sequence handshakes
&lt;br&gt;or by sending DTLS packets with a future epoch.
&lt;br&gt;&lt;br&gt;A mistake in handling return codes allows a remote attacker to spoof
&lt;br&gt;DSA signatures on data or certificates.
&lt;br&gt;&lt;br&gt;These vulnerabilities have been assigned CVE-2009-1377, CVE-2009-1378,
&lt;br&gt;CVE-2009-1379, CVE-2009-1386 and CVE-2009-1387.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;The OpenSSL library does not limit the number of buffered DTLS records
&lt;br&gt;tagged with a future epoch. If a large amount of such packages is
&lt;br&gt;received, the DTLS records will occupy large amounts of memory, causing
&lt;br&gt;exhaustion. Also, no limit is imposed on the number of out-of-sequence
&lt;br&gt;handshake messages received, which can also be used to exhaust all
&lt;br&gt;available memory.
&lt;br&gt;&lt;br&gt;A different error is caused by the functions validating DSA and ECDSA
&lt;br&gt;keys. These functions do not handle the return code of
&lt;br&gt;EVP_VerifyFinal() properly, causing some types of signature verification
&lt;br&gt;errors to be ignored. This can be used to spoof DSA signatures on
&lt;br&gt;data or certificates.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;No workaround to the problem is currently known. Users are advised
&lt;br&gt;to either restrict access to OpenSSL services to trusted users only
&lt;br&gt;or to apply the patches as described below.
&lt;br&gt;&lt;br&gt;The following instructions describe how to upgrade your OpenSSL
&lt;br&gt;binaries by updating your source tree and rebuilding and
&lt;br&gt;installing a new version of OpenSSL.
&lt;br&gt;&lt;br&gt;* NetBSD-current:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD-current dated from before 2009-07-04
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; should be upgraded to NetBSD-current dated 2009-07-05 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-current CVS branch (aka HEAD):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; crypto/dist/openssl
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install OpenSSL:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P crypto/dist/openssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd lib/libcrypt
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../usr.bin/openssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; If you use the patented libcrypto extensions,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; you will also want to execute the following commands:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../lib/libcrypto_idea
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto_mdc2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto_rc5
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&lt;br&gt;* NetBSD 5.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 5.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-04 should be upgraded from NetBSD 5.* sources dated
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-05 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.1 and 5.0.1 will include the fix.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-5 or netbsd-5-0 branches:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; crypto/dist/openssl
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install OpenSSL:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P crypto/dist/openssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd lib/libcrypt
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../usr.bin/openssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; If you use the patented libcrypto extensions,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; you will also want to execute the following commands:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../lib/libcrypto_idea
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto_mdc2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto_rc5
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&lt;br&gt;* NetBSD 4.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 4.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-04 should be upgraded from NetBSD 4.* sources dated
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-05 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.1 and 4.0.2 will include the fix.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-4 or netbsd-4-0 branches:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; crypto/dist/openssl
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install OpenSSL:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P crypto/dist/openssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd lib/libcrypt
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../usr.bin/openssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; If you use the patented libcrypto extensions,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; you will also want to execute the following commands:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../lib/libcrypto_idea
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto_mdc2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto_rc5
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;Daniel Mentz and the Google Security Team for discovering the vulnerabilities
&lt;br&gt;and reporting them to the vendor.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-07	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at 
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-009.txt.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-009.txt,v 1.1 2009/07/07 21:57:15 tonnerre Exp $
&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQIcBAEBAgAGBQJKU8fzAAoJEAZJc6xMSnBuUZAQAKtILf4tYU6tpRvYaoWqA4+2
&lt;br&gt;Co7wT+h0ihGJDgK2vRSXd+gG+rAhh3vi0b4nfuJY/zHotVC1l5Y50jLB4BSP/ZbR
&lt;br&gt;STP2oBx87C1qmufqRW6fpe8rifelE9O3qmixSvogupro/zQXXaVrwnhNJPSjZ+o0
&lt;br&gt;uZ1SWZr78UGBcyFgtOKhBD6p9wXpNl5R7by7V4qjxB+Q0a/tPwJ6Qb2mjWYE3Aj8
&lt;br&gt;BfedB/5z2eP5rsmA89yk6m9cmm15n3OEtq/lqYDyRdnZTz8QnNvWEm/byVmjqDwu
&lt;br&gt;lMVtSq4QmGkS97NVCrkkb9mAYm6rqaTaxlMVKQRoWVf1CSy3ZYTDjJNmp0kCWLct
&lt;br&gt;gN9AXi+9TqL9/H1tuvqpzEHHVFJh+KSxB8bayzAz4ODPbcXeSv+mNKwQF7ryO+Kk
&lt;br&gt;VenqjcD/0JSmX66hDwC4RfDTmYoqcKVOpRKhHmHLsrQ53Gv56gX+5z8r4Lcz4hH5
&lt;br&gt;3a6oo6GG2jzJJaz6W9C+k1G4WQklgc4CpL3t9qJsnJ2947Dc7qELj2C20iEXSNcR
&lt;br&gt;VcwlSYK4Niyf7IwNjcNZaXexzIfYDByEBLWtXCbSrBEwAI3TdSstlEafHYsBVXa3
&lt;br&gt;+xWJpqjFsb+2CPlFwRDIdA2Mhp7MojHFaPvsdj4Y6EfN5KVLsLmhzMpmtP0XeCsm
&lt;br&gt;Iosoo4fBPrIeYefwxcNs
&lt;br&gt;=64Ku
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-009%3A-OpenSSL-DTLS-Memory-Exhaustion-and-DSA-signature-verification-vulnerabilities-tp24390494p24390494.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24390458</id>
	<title>NetBSD Security Advisory 2009-008: OpenSSL ASN1 parsing denial of service and CMS signature verification weakness</title>
	<published>2009-07-07T21:45:29Z</published>
	<updated>2009-07-07T21:45:29Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-008
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		OpenSSL ASN1 parsing denial of service and CMS
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; signature verification weakness
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:		affected prior to 2009-03-27
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:		not affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.*:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc:			openssl package prior to 0.9.8k
&lt;br&gt;&lt;br&gt;Severity:	Denial of Service, Forgery of CMS signatures
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current:		May 27, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4 branch:	July 4, 2009 (4.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4-0 branch:	July 4, 2009 (4.0.2 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc 2009Q1:		openssl-0.9.8k corrects this issue
&lt;br&gt;&lt;br&gt;Please note that NetBSD releases prior to 4.0, as well as the pre-release
&lt;br&gt;versions of NetBSD 5.0, are no longer supported. It is recommended that
&lt;br&gt;all users upgrade to a supported release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;A handling error in the ASN1 parser functions can cause an
&lt;br&gt;application linked against libcrypto to crash. Another
&lt;br&gt;vulnerability in the CMS signature verification algorithm
&lt;br&gt;allows an attacker to modify the CMS attributes of a signed
&lt;br&gt;certificate.
&lt;br&gt;&lt;br&gt;This vulnerability has been assigned CVE-2009-0590,
&lt;br&gt;CVE-2009-0591 and CVE-2009-0789.
&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;The function ASN1_STRING_print_ex() when used to print a BMPString
&lt;br&gt;or UniversalString will crash with an invalid memory access if the
&lt;br&gt;encoded length of the string is illegal.
&lt;br&gt;&lt;br&gt;An error calculating the length of ASN1 structure members can be
&lt;br&gt;exploit to cause a memory access violation in the error path on
&lt;br&gt;architectures where sizeof(long) &amp;lt; sizeof(void *), causing an
&lt;br&gt;application linked against a vulnerable version of libcrypto to
&lt;br&gt;crash.
&lt;br&gt;&lt;br&gt;The function CMS_verify() does not correctly handle an error
&lt;br&gt;condition involving malformed signed attributes. This will cause an
&lt;br&gt;invalid set of signed attributes to appear valid and content
&lt;br&gt;digests will not be checked.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;Currently, no workaround to this problem is known. Users must
&lt;br&gt;either upgrade their OpenSSL version to include the fix, or
&lt;br&gt;to restrict access to affected applications to trusted users
&lt;br&gt;only.
&lt;br&gt;&lt;br&gt;The following instructions describe how to upgrade your OpenSSL
&lt;br&gt;binaries by updating your source tree and rebuilding and
&lt;br&gt;installing a new version of OpenSSL.
&lt;br&gt;&lt;br&gt;* NetBSD-current:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD-current dated from before 2009-03-27
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; should be upgraded to NetBSD-current dated 2009-03-28 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-current CVS branch (aka HEAD):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; crypto/dist/openssl
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install OpenSSL:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P crypto/dist/openssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd lib/libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../usr.bin/openssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; If you use the patented libcrypto extensions,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; you will also want to execute the following commands:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../lib/libcrypto_idea
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto_mdc2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto_rc5
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&lt;br&gt;&lt;br&gt;* NetBSD 4.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 4.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-04 should be upgraded from NetBSD 4.* sources dated
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-05 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.1 and 4.0.2 will include the fix.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following files/directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-4 or netbsd-4-0 branches:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; crypto/dist/openssl
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install OpenSSL:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -r &amp;lt;branch_name&amp;gt; -d -P crypto/dist/openssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd lib/libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../usr.bin/openssl
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; If you use the patented libcrypto extensions,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; you will also want to execute the following commands:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../../lib/libcrypto_idea
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto_mdc2
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd ../libcrypto_rc5
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no includes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;Ivan Nestlerode of IBM and Paolo Ganci for discovering and reporting
&lt;br&gt;these issues.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-07-07	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at 
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-008.txt.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-008.txt,v 1.1 2009/07/07 21:57:15 tonnerre Exp $
&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQIcBAEBAgAGBQJKU8fnAAoJEAZJc6xMSnBu3tQP/A27N0vjPgawbMJ2ugtw8bVR
&lt;br&gt;oRi95Vl0Qgvn3dAge37LIUd7xCYo7RuPcvJn23ua0DcTmObkc0HO0kiaucn/O7BQ
&lt;br&gt;He794oEwtEzDv8oQYhKuRLGZQV9bzWfjHebmHWBH35FZtqZ5ujV1Anrf7cSmjKEY
&lt;br&gt;wTmrUUws+/v3rdZ4HgXOzNiqyie17oN5QoX3iLmtQILTecLH15R6pv9SgBV003dz
&lt;br&gt;/zy8ypKkshSfBXczLpHemOmlFh5wCH7vvsAnIgyXLKYCQ580zyyc6GQEOUBCw0uh
&lt;br&gt;Id7A2DuksbB4/jtq0cZBqXa7kWjM4Ypufoxa/G5cbQMRTWeVdfDidc5Qismis6q+
&lt;br&gt;gqAl6+7R7ZS4Txzp2Ve3bvN+dgXTyjYscWE59It8br1RnMY7sM/Ad8PlwCRbrLGs
&lt;br&gt;0AA+tvF4yemQjgoSIbV2FBi8ZYyOkQH3mxgnuS/p7AXQLtEuz3wLmSuHFKnfHK7A
&lt;br&gt;ikijnSOkj3u1Rrk0AqTYOsUQifzwdn7wkzyTSGWsIYYpUURJEmRFlmizM2tGRciR
&lt;br&gt;411ND8lPOB3eI6FonbeWPfFrd3nAOfsI9+3IcA8Ez3wWTYD0X/dw36cJT1m66dou
&lt;br&gt;SqEN6ibFeR70grJo6nuO4sH8G7e/9QkFesdccJhaRFgJ7D0Fc28WwLQohx9H9tnG
&lt;br&gt;7Bnl8Q6GvEzktaYZeqOw
&lt;br&gt;=eMbN
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-008%3A-OpenSSL-ASN1-parsing-denial-of-service-and-CMS-signature-verification-weakness-tp24390458p24390458.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24281670</id>
	<title>NetBSD Security Advisory 2009-007: Buffer overflows in hack(6)</title>
	<published>2009-06-30T14:52:12Z</published>
	<updated>2009-06-30T14:52:12Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-007
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		Buffer overflows in hack(6)
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:	source prior to June 30, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.1:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:		affected
&lt;br&gt;&lt;br&gt;Severity:	Unprivileged local users can gain access to &amp;quot;games&amp;quot; group
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current:		June 29, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5 branch:	June 29, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (5.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5-0 branch:	June 29, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (5.0.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4 branch:	June 29, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (4.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4-0 branch:	June 29, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (4.0.2 will include the fix)
&lt;br&gt;&lt;br&gt;&lt;br&gt;Please note that NetBSD releases prior to 4.0 are no longer supported.
&lt;br&gt;It is recommended that all users upgrade to a supported release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;Hack, a &amp;quot;rogue-like&amp;quot; game, is installed setgid to the &amp;quot;games&amp;quot; group
&lt;br&gt;to allow access to shared data and high scores and allow saved games
&lt;br&gt;to be stored where they cannot be tampered with. Buffer handling
&lt;br&gt;shortcomings allow arbitrary code execution with the privilege of the
&lt;br&gt;&amp;quot;games&amp;quot; group, which can then be used to attack other users playing
&lt;br&gt;games.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;The gethdate() function contains a stack-based buffer overflow
&lt;br&gt;vulnerability that can be exploited by setting the PATH environment
&lt;br&gt;variable.
&lt;br&gt;&lt;br&gt;The main() function contains a data-segment-based buffer overflow bug
&lt;br&gt;attackable in wizard mode by the GENOCIDED environment variable; this
&lt;br&gt;may be exploitable via function pointers elsewhere in the data segment.
&lt;br&gt;&lt;br&gt;Multiple other string handling weaknesses exist that may or may not be
&lt;br&gt;attackable and may or may not be exploitable.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;Removing the setgid bit from /usr/games/hack is a simple and effective
&lt;br&gt;workaround, although hack will not work properly without it.
&lt;br&gt;&lt;br&gt;For all affected NetBSD versions, the proper fix requires obtaining
&lt;br&gt;updated sources, and rebuilding and installing hack. Fixed sources may
&lt;br&gt;be obtained from the NetBSD CVS repository.
&lt;br&gt;&lt;br&gt;* NetBSD-current:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD-current dated from before 2009-06-30
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; should be upgraded to NetBSD-current dated 2009-06-30 or later.
&lt;br&gt;&lt;br&gt;* NetBSD 5.0_STABLE and 5.0.0_PATCH:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The binary distribution of NetBSD 5.0 is vulnerable.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 5.0 sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-30 should be upgraded from NetBSD 5.0 sources
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dated 2009-06-30 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0.1 and 5.1 will include the fix.
&lt;br&gt;&lt;br&gt;* NetBSD 4.0_STABLE and 4.0.1_PATCH:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The binary distribution of NetBSD 4.0 is vulnerable.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 4.0 sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-30 should be upgraded from NetBSD 4.0 sources
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dated 2009-06-30 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.2 and 4.1 will include the fix.
&lt;br&gt;&lt;br&gt;* For all releases:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; appropriate CVS branch:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; games/hack
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install hack:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P games/hack
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd games/hack
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir obj
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no dependall install
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; This will select the fixes for the branch you have already
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; checked out in your source tree.
&lt;br&gt;&lt;br&gt;&lt;br&gt;For more information on building (oriented towards rebuilding the
&lt;br&gt;entire system, however) see:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.netbsd.org/guide/en/chap-build.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.netbsd.org/guide/en/chap-build.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;David A. Holland found and fixed the problems.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-30	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at 
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-007.txt.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-007.txt.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-007.txt,v 1.1 2009/06/30 18:48:33 tonnerre Exp $
&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQIcBAEBAgAGBQJKSl6pAAoJEAZJc6xMSnBuvToP+gJN7pXD5M1Sd8/lG+bM5DQr
&lt;br&gt;nxSAlOzww0gzIJPxvvkYNWooQM3wW2OdvqTrIiN6UMTtAXsuw4UFsnbiwUorj8rZ
&lt;br&gt;XexgNO8hK5MyqebpsCwzH7Ofcip5yozBspBcE5bOVXQZcRKrUprvS+Zk9Q141ObV
&lt;br&gt;NZ6qY2y9NjRE4lKzXMsxTLQHhFPMVTC+nG4rke4RrFIur11xdT1xIW59iuJExVTs
&lt;br&gt;5eqFE/yOgmVondPCaln830beho3wHIha4obYXYq0+C2xbFzNvNu0+mAIKxkNhxel
&lt;br&gt;902vLMHolzp664mSrKNxJwV2es3ii0NMMGlnGGecIsz+RedvizG2wcdEWCTumLEw
&lt;br&gt;jIJY448FsI1a2GKHbOH5N/TieidHbEq81v8H0k2Kkw5B0GlwARsW8iCDVNeGpmKr
&lt;br&gt;0F5Zqy2M0EvNfGykPw+Rd+vU7soid4JFJVlnGoEFt2BbhtMz7XlT8xovy4I4Sgp0
&lt;br&gt;1klYEwB8Y8quipJnN9tmyAX3eVH73s0ycA4mjlSFtsvMZDTU0xr0znC1gaCcWtia
&lt;br&gt;gfq1pLgyH1BNgg2TuAon2kGwON2T/FzSoJySSjujWq9LXLKj3ZEhqCRTmQ9m+cHr
&lt;br&gt;jpI0Lx4gSxixKlH+ROv6Y/6bmc8+W0JUtHkUIkEtj/PeJ/GBVCBjEOzShCkvep6t
&lt;br&gt;qYfYnSqAMzMWrCl6ARb5
&lt;br&gt;=7nGK
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-007%3A-Buffer-overflows-in-hack%286%29-tp24281670p24281670.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24281628</id>
	<title>NetBSD Security Advisory 2009-006: Buffer overflows in ntp</title>
	<published>2009-06-30T14:51:34Z</published>
	<updated>2009-06-30T14:51:34Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-006
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		Buffer overflows in ntp
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:	source prior to May 21, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:		source prior to May 27, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.1:		source prior to May 27, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:		source prior to May 27, 2009
&lt;br&gt;&lt;br&gt;Severity:	Potential remote arbitrary code execution
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current:		May 20, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5 branch:	May 27, 2008 (5.0.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4 branch:	May 27, 2008 (4.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4-0 branch:	May 27, 2008 (4.0.2 will include the fix)
&lt;br&gt;&lt;br&gt;&lt;br&gt;Please note that NetBSD releases prior to 4.0 are no longer supported.
&lt;br&gt;It is recommended that all users upgrade to a supported release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;Two remote buffer overflow vulnerabilities have been found in the ntp
&lt;br&gt;(Network Time Protocol) code.
&lt;br&gt;&lt;br&gt;The first, in ntpq, potentially allows arbitrary code execution (as
&lt;br&gt;the user running ntpq) if a hostile ntp daemon is contacted.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0159&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0159&lt;/a&gt;&lt;br&gt;&lt;br&gt;The second, in ntpd itself, allows remote arbitrary code execution as
&lt;br&gt;the system ntp user if cryptographic authentication is enabled, which
&lt;br&gt;is not the default. If ntpd is configured to run in a chroot area
&lt;br&gt;(which is not the default) the arbitrary code execution should be
&lt;br&gt;contained within the chroot.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252&lt;/a&gt;&lt;br&gt;&lt;br&gt;The second of these vulnerabilities makes the first considerably more
&lt;br&gt;dangerous than it would be on its own.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;1. The cookedprint() function contains a stack-based buffer overflow
&lt;br&gt;vulnerability that can be exploited by sending a properly crafted
&lt;br&gt;response to ntpq.
&lt;br&gt;&lt;br&gt;2. The crypto_recv() function contains a stack-based buffer overflow
&lt;br&gt;vulnerability that can be exploited by sending a properly crafted
&lt;br&gt;packet to ntpd.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;Workarounds:
&lt;br&gt;&lt;br&gt;1. Avoid running ntpq until a fixed version has been installed.
&lt;br&gt;&lt;br&gt;2. Disable cryptographic authentication until a fixed version has been
&lt;br&gt;installed. Or, disable ntpd entirely until a fixed version has been
&lt;br&gt;installed. Either of these approaches is probably undesirable; it is
&lt;br&gt;better to update immediately.
&lt;br&gt;&lt;br&gt;Enabling the rc.conf(5) option to run ntpd under chroot may mitigate
&lt;br&gt;the impact of an attack but does not qualify as a real workaround.
&lt;br&gt;&lt;br&gt;Solutions:
&lt;br&gt;&lt;br&gt;For all affected NetBSD versions, obtain updated sources, and
&lt;br&gt;rebuild and reinstall the ntp daemon and tools. If ntpd is running, be
&lt;br&gt;sure to stop and restart it.
&lt;br&gt;&lt;br&gt;The fixed sources may be obtained from the NetBSD CVS repository.
&lt;br&gt;&lt;br&gt;The following instructions briefly summarize how to update and
&lt;br&gt;recompile your ntp binaries by updating your source tree and rebuilding
&lt;br&gt;a new version of ntp.
&lt;br&gt;&lt;br&gt;* NetBSD-current:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD-current dated from before 2009-05-20
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; should be upgraded to NetBSD-current dated 2009-05-21 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-current CVS branch (aka HEAD):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/ntp/ntpd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/ntp/ntpq
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install ntp:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P dist/ntp/ntpd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P dist/ntp/ntpq
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/ntp
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # /etc/rc.d/ntpd stop
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # /etc/rc.d/ntpd start
&lt;br&gt;&lt;br&gt;&lt;br&gt;* NetBSD 5.0:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The binary distribution of NetBSD 5.0 is vulnerable.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 5.0 sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-05-27 should be upgraded from NetBSD 5.0 sources
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dated 2009-05-28 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0.1 and 5.1 will include the fix.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-5-0 CVS branch:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/ntp/ntpd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/ntp/ntpq
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install ntp:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P -r netbsd-5-0 dist/ntp/ntpd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P -r netbsd-5-0 dist/ntp/ntpq
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/ntp
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # /etc/rc.d/ntpd stop
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # /etc/rc.d/ntpd start
&lt;br&gt;&lt;br&gt;&lt;br&gt;* NetBSD 4.0, 4.0.1:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The binary distributions of NetBSD 4.0 and 4.0.1 are vulnerable.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 4.0 sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-05-27 should be upgraded from NetBSD 4.0 sources dated
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-05-28 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.1 and 4.0.2 will include the fix.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-4-0 CVS branch:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/ntp/ntpd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/ntp/ntpq
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install ntp:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P -r netbsd-4-0 dist/ntp/ntpd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P -r netbsd-4-0 dist/ntp/ntpq
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/ntp
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # /etc/rc.d/ntpd stop
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # /etc/rc.d/ntpd start
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;Christos Zoulas for providing the fixes.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-30	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at 
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-006.txt.asc&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-006.txt.asc&lt;/a&gt;&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-006.txt,v 1.2 2009/06/30 18:30:27 tonnerre Exp $
&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQIcBAEBAgAGBQJKSl6gAAoJEAZJc6xMSnBux40QALdvcTyn12pJ22i72eLn1aEh
&lt;br&gt;UcXNvekD0yQFXF3xQ/2klcVCmUvFelSlkvelZ2csDxzetvNSRVY6SBgp3F6NdWC3
&lt;br&gt;YxDAiDF/GeZyQi2hWdCqLVsW2kfDih8Bl+sL/51oxuIkzaSQzkQAhXCF3ggWl259
&lt;br&gt;oLMeuR/Vdre6jqJpfXjq12vhNu7g/XvLyhH7b7WAMxqT/+7rEqmlPua5epjr43b2
&lt;br&gt;RMt4zCRFga+NlU+iO78YvzEAUhk/kvFhDkXiPMQZ0puY4akuRAMYS1Il8YkK0o8K
&lt;br&gt;rktvX9dMChnIFyh826vuiUpeUpN/UxHRUYTIkUhO8A4WoM6ffs3GuJ0IXZUQPmoV
&lt;br&gt;mZ/ybpJWjRmAQnwK2vw/RJAhPQnojzZ0ZqFYry1zvlw8Ec59ShNO8XUXXMnxCeK6
&lt;br&gt;kZsJ1pWuHc+m6aQ0lkItuV6zBnx4xjTSJ8bzE1qIkX9v0kFYkny8hzxNWRHrhZhu
&lt;br&gt;qm4acnPdzWivfo1C9panMSI3oL8z0wAG6s5gkBJDglbdwtyaM+W3r3EAHvyaKmSV
&lt;br&gt;1uubeTGTh8pqkTNsPAL8+OkFRCAlU2NQZWjbkjwJQfbHaRzdD/BJzO/9JFJ0aYhX
&lt;br&gt;H0Eo0fBotfCcUhl5jzo5r4EnsFuSmeaLDLExVY7NNcqYylrlUnj31MUJh6TL/Gan
&lt;br&gt;3vWY3qzD4Z2V7lwVgzwX
&lt;br&gt;=zdxv
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-006%3A-Buffer-overflows-in-ntp-tp24281628p24281628.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24176262</id>
	<title>Changing the NetBSD Security Officer PGP key</title>
	<published>2009-06-23T15:41:54Z</published>
	<updated>2009-06-23T15:41:54Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">Dear NetBSD users, dear followers of the NetBSD security community,
&lt;br&gt;&lt;br&gt;Please note that from now on, the NetBSD Security Officer will
&lt;br&gt;use a new PGP key to sign announcements and other types of
&lt;br&gt;communication. The old PGP key will be unenrolled over the next
&lt;br&gt;time:
&lt;br&gt;&lt;br&gt;pub &amp;nbsp; 1024R/F8376205 1997-07-01
&lt;br&gt;uid &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=24176262&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-officer@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;It will be superseeded by the following key which is larger
&lt;br&gt;and offers a better security margin:
&lt;br&gt;&lt;br&gt;pub &amp;nbsp; 4096R/4C4A706E 2009-06-23 [expires: 2019-06-21]
&lt;br&gt;uid &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Officer &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=24176262&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;security-officer@...&lt;/a&gt;&amp;gt;
&lt;br&gt;sub &amp;nbsp; 4096R/DF2CE620 2009-06-23 [expires: 2019-06-21]
&lt;br&gt;&lt;br&gt;The key will be rotated on a regular basis in the future, for
&lt;br&gt;better security of our users. Please update your processes to
&lt;br&gt;make use of this new key in the future.
&lt;br&gt;&lt;br&gt;To testify this migration, this mail contains the new security-officer
&lt;br&gt;PGP key below and, appended, a signature of the text part generated
&lt;br&gt;with the old and the new key, correspondingly.
&lt;br&gt;&lt;br&gt;Thank you for your continued trust in NetBSD,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The NetBSD Security Officers
&lt;br&gt;&lt;br&gt;-----BEGIN PGP PUBLIC KEY BLOCK-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;mQINBEpBSlIBEADZ07j5C/Gt+frfs/Jj1Sa3Ac5iwathJQQvoA6AAh860juEugdG
&lt;br&gt;yBXtJDRiXRLP/t7MX16BcyYxMRc15WPSnjpolyM7PPnbOHoLcrmlkdWyzjJfTXCR
&lt;br&gt;XMIG2wOYgER4fNjFmf0uD+EcEUQA2ShXUpviQBIs6GLlDLPvzKmtHzX4I1WWKzm4
&lt;br&gt;xe/ik64YcL5pW2Wd/mLNd97FDmxwjRnUm4JEUYNUMbMOleytGGvNzKihpIvyIVCv
&lt;br&gt;MEfZfRfPl1hPXHqKs9H8u2UuNn6DJDWmHN738X95VDOv2YReIG8CwLqpnKv7BCEN
&lt;br&gt;m1/XnbxEC6lExrG2PCfWeyM9xFh3Q4oGZ19qo8m6jRWUlwY3hNQ7eSYoJZNkkjGZ
&lt;br&gt;Ooc09BNTcM/M7oTUgifDBFwORiW64weGSgpICN/BN+vifQUIOgJ6g3LHmi6RXmFk
&lt;br&gt;GbMLBsOni/j0ZHbIJacMoI/82h7XykOl1wZ3xzb9Hj0sNqSO+TeDEA2BVt1JKweH
&lt;br&gt;w0nD23zBa5Md9w+xhigdXaTcDp6JmJOUXb8p4J/uXiwJa2yjIQ0IxSH7Adq76oKK
&lt;br&gt;+ALanhOs07kiDHLy/ZwgjBrynEfvDb8f6LH4hDZNm6QuGrbboAYRxo7B8vvYn7qj
&lt;br&gt;kiNRI53VRxbohFbhu1YUh4EIZgTgBwzos1zXVmkP5SmhSnreOJ3mAPAFEwARAQAB
&lt;br&gt;tDVOZXRCU0QgU2VjdXJpdHkgT2ZmaWNlciA8c2VjdXJpdHktb2ZmaWNlckBOZXRC
&lt;br&gt;U0Qub3JnPokCPQQTAQIAJwUCSkFKUgIbAwUJEswDAAcLCQgHAwIBBBUCCAMEFgID
&lt;br&gt;AQIeAQIXgAAKCRAGSXOsTEpwbpexD/9rdMz3AvYeTF3FexE7LQhKpOTu0vT1qep+
&lt;br&gt;ArEg+LlKhD+2H0lj8e7rQBbOTlJE7kgxNvGmBBqhxgz/fuSk6+GN0FC/A+l4uDum
&lt;br&gt;bAiZVukLDopF/51Hjv10P/AL3pl/OBhKEoRDLVxb/x4vn+sB4qHyEraG/KQgEE6x
&lt;br&gt;ocKVWBbSB5ohRPa5kn/7yQo5+DciJzRYZ9g0g78dMhFeHN20C8oz7nu6MgrJ77vj
&lt;br&gt;StjEhrQlCt2xaXa5HXCq1L9reqqOdiRCXuyxoDL2ZzsLKWbqouM/ejNXZeumvBUF
&lt;br&gt;+zf8n2Y1WQqD1VTHzxZqJoywgpSjyPc7ddzYNaLc/H9RRtBluxb6e+pSIeJOz+sq
&lt;br&gt;SIRsYBGm3qW/AuMTSmp4p6PvKWaOIBTa8IFvGb2aQbqoBZ4q6CqAMkuUMXxUzpoa
&lt;br&gt;OjQ2uA5jVrYDb8VMugRGN94duUxILZa0Ioq8MjqHdtK2Y7kgHG1kybGQJo0ZAsrf
&lt;br&gt;vKLo815OXonUUd2Vjy1Yol5yCZ49A2PIeSFZy7/q4CXAu0xIFscNzKpPlD7CKGjQ
&lt;br&gt;uZ4m+99feJApBPrggS2HecI9Pm4lfkbXEE4UFJ1mnmsDp+LAAADF8odL5VoS5YvU
&lt;br&gt;ent+hrLxnjxSdTQYPj8pezQCTgK5Ra/fUUTQXeJoaktNVmfs5I0P93EgHod6cr6i
&lt;br&gt;uAQlspMm67kCDQRKQUrAARAA8+HXXFhDrtGuM1X2DSWdAJICEyi3nRshwGzSNOSF
&lt;br&gt;29tMv0ADgdyEQQ2pxp6H7FbP8MrLN6dGPUZN0H/2/ziz+VpWT9q64WArTEVo99sb
&lt;br&gt;jnoJELSQQxUl0JL2Kkfdnj3M/irnx0vQKrNiZXcadPp7h9yt8fGMQWjrkLiIENQ5
&lt;br&gt;glCRQTd0JnN9f+MGejMDMdLowrKPSQlPix5YjYgFw8v9zHXacymWsoqDYDxSaPhJ
&lt;br&gt;jAlu6wl/dkDIpuF3GaphrITPQYz4mmg0t1i9MWn8zpuCD/kGKLpNDSC+14SlHRGB
&lt;br&gt;cXL8s0mUH7DhRZkJPplxPoYzMT/oyVeA3/jtMdA4HLDn1+hDzHa1QiodKm3TL7Tv
&lt;br&gt;qEARLjSc91Bh2nqV+WKKlMKZbtrhuxYokva7+IPxhm3fE1ZOp7xJ5lh6oAimjDH4
&lt;br&gt;klgZMNiSz2eh13B6dwhXSBacyXsNUGjuLE9WN+CAZpE3fLCjaRh8dVuaNGq+x41U
&lt;br&gt;VlobM+qvtpPyUHBG/zehH/sy3gnPz4+7dy3zgkM4wDAyxe2B4M78ZGsIZhHm31kH
&lt;br&gt;bO2PjV7LMxESGTOxjz+gqRHuwsczqNHPN6Y1M1yncCm6WRncVTpdHQjgkpvuO4IX
&lt;br&gt;4yTx+ssGPr63yFxONB2CYYCzJ3Ky36qcllNbZA7Aecf9pre3jB9vdmWej5yn4d2X
&lt;br&gt;hSMAEQEAAYkCJQQYAQIADwUCSkFKwAIbDAUJEswDAAAKCRAGSXOsTEpwbs25D/0V
&lt;br&gt;D6I3GYTuvDiI4k/ABbnu4cSlbTbXL3nlEjAOqhpgjHXG0x/3PV48R+7ASpu1PUTh
&lt;br&gt;SUJCx4O0pk/UPI/RPB5NBj7aseHZNwhYrrYqILgm+8zuudXwl7iZ1hE4n/TCuqn+
&lt;br&gt;oDOufeBb0hKE4a66BNmMx9nYkAO10OLpY/hGSlt15CzdDWrXLmENTswbcL3B6na0
&lt;br&gt;IU7iDjqHQqc1j+wMcsRdfcjVGGtLJpv2qvV49CiYIuljTxoTVN137LU7aXCqyvJU
&lt;br&gt;1Nx63omLRhwnp3EzM+2ag7t8Y8zsvuU50vrvm4AIurtgcCzx4gQXO8tNb6ZCPRr6
&lt;br&gt;FcdxwX8ZHvq/BIqrnt3R4ee3fmoIbfsorOT/HFaekCqm5Mgz/lwCrKXMCQGl1xpO
&lt;br&gt;HYQ8JhvGG4zKd8CJslpu7t5Yn1eQZj87J1vbzA7K9wmtEIrLHnPBcyZyHJT/73Ip
&lt;br&gt;q9QVRHqNaotjM0Jsmpwn1uztSS2zmB9ugrRPJrllkoozcnETxaVCiblLBGGixfo0
&lt;br&gt;DAOC2n+WsApGhZJafujVJ4aXxsD3XxTXgrx0QBanOQmiksBdsOytmeuibScbEtyC
&lt;br&gt;lVfAHOTENBr2V3ozhH9ghlbm8Io2kg31/xKQlcqLmtEut5uMbrjqeWz7ICrNBDDl
&lt;br&gt;lZVYSg38QEDQ4fSPkYd00g5aPUrWbQvlW7jeuqXx8A==
&lt;br&gt;=VfLo
&lt;br&gt;-----END PGP PUBLIC KEY BLOCK-----
&lt;br&gt;&lt;br /&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQCVAwUASkFW6D5Ru2/4N2IFAQI7zAP/Z99a6nFpb+eesF4omoaDuUZ85lMDX3gY
&lt;br&gt;p2C8LVQXGIVocTnuXBcUMt3gl94I3FthVAINKL/IW7rQFvi/AfL6PsNxkNuS0BDE
&lt;br&gt;ESUrGJkvquGLucKQufqGgqtxQIMVZmiOclFDeoC16OZlDIM2W9PoheX9oR40K81g
&lt;br&gt;YLLX3MNlpdM=
&lt;br&gt;=mEWT
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;&lt;br /&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQIcBAABAgAGBQJKQVcUAAoJEAZJc6xMSnBuRiUP/Re11cPMsfuyVrMUqKrb7tcU
&lt;br&gt;ALJnnf/P4udYNZoNv89giVm6XjmYOSMYdqLSjJ88nkaELFRyjUVdeXRK1rJ2B9Se
&lt;br&gt;z78N2HltWlO9Id49lwnKRBC3+3TAnEoRjZ2QwIZ6qEbrs8Kx1cPZlJG9qmkG/gH5
&lt;br&gt;AsocslJRchM9IVJMvMKRULQS8r1+kQU1f8sOIyRo5m1yfgwlSEoBMpaAvPcQ8fm+
&lt;br&gt;HzRVjTbYSKTIgfIXUdQchDUCxuVrOUmOg7MfUpbnTANGOa2ihS9N00swAhSSamoK
&lt;br&gt;FTtraZDHeZnG1E4i+FJGUjvSRajvUl9DA3oX/8uUH91VFVTjLWvc5QlN745cEr4i
&lt;br&gt;lC1Bl8c4SdCPd7LC+MH/iCy82E6TQTxVcCQg5xzFNJLYAliwGP+TVb7gh5JmhbTn
&lt;br&gt;YWD2T5X5gt5e5Zxomp0/Z5omV2N+GEWWCcgl5DKzqTXuPIzRkGtqsMxM8Kbh8aPT
&lt;br&gt;95BDRgIcNQqSXt9KowO4KdrCCa2oFaknfMguaDpIVz7eedxg+pDsKQg4SZd3oQfy
&lt;br&gt;3RTndqDyMDjTJOD4kzGSsBIRnL5t+kG6M0Aq7qG2SC1JdD1JgFA8RfdDAbXYAT85
&lt;br&gt;g6Z5epEdXdrwe3x3d6JdW604EiKlnVv7XwXQKNXwX3kIfrdCSXSoCsvt3QTQQ+jv
&lt;br&gt;s+hiCG5u1deWcUaaeRus
&lt;br&gt;=T61Y
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Changing-the-NetBSD-Security-Officer-PGP-key-tp24176262p24176262.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24174567</id>
	<title>NetBSD Security Advisory 2009-004: NetBSD OpenPAM passwd(1) changing weakness</title>
	<published>2009-06-23T14:01:38Z</published>
	<updated>2009-06-23T14:01:38Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-004
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		NetBSD OpenPAM passwd(1) changing weakness
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:		affected before June 14, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.1:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:		affected
&lt;br&gt;&lt;br&gt;Severity:	Change root password as normal user
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current:		June 14, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5-0 branch:	June 18, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (5.0.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5 branch:	June 18, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (5.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4-0 branch:	June 18, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (4.0.2 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4 branch:	June 18, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (4.1 will include the fix)
&lt;br&gt;&lt;br&gt;&lt;br&gt;Please note that NetBSD releases prior to 4.0 are no longer supported.
&lt;br&gt;It is recommended that all users upgrade to a supported release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;A verification weakness in the pam_unix module allows an authenticated
&lt;br&gt;attacker with knowledge of the current root password to reset it.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;The pam_unix authentication module provided by NetBSD does not verify
&lt;br&gt;the user invoking a password change properly. This allows an
&lt;br&gt;authenticated, unprivileged user to change the root password, given
&lt;br&gt;the old root password.
&lt;br&gt;&lt;br&gt;Authentication as root is typically limited to members of a special
&lt;br&gt;group called &amp;quot;wheel&amp;quot; in order to limit the impact of a leaked root
&lt;br&gt;password. For this reason, the ability of changing the root password
&lt;br&gt;is traditionally limited to users who have already authenticated as
&lt;br&gt;root.
&lt;br&gt;&lt;br&gt;Please note that this only affects systems using normal UNIX password
&lt;br&gt;authentication.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;In order to verify if you are affected by the problem, look for a line
&lt;br&gt;in /etc/pam.d/system stating
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; password	required	pam_unix.so	no_warn try_first_pass
&lt;br&gt;&lt;br&gt;If such a line exists, invoke the command
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; passwd root
&lt;br&gt;&lt;br&gt;as a regular user. If the command issues the error &amp;quot;Unable to change
&lt;br&gt;auth token: permission denied&amp;quot;, the system is not affected.
&lt;br&gt;&lt;br&gt;A temporary workaround is to add the line
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; password	prerequisite	pam_group.so	no_warn group=wheel fail_safe
&lt;br&gt;&lt;br&gt;before the pam_unix line to /etc/pam.d/system. This allows only members
&lt;br&gt;of the wheel group to change passwords until the issue can be addressed.
&lt;br&gt;Note however that this can increase the time user accounts are
&lt;br&gt;compromised in case of a security incident.
&lt;br&gt;&lt;br&gt;For all NetBSD versions, you need to obtain the fixed NetBSD sources and
&lt;br&gt;rebuild and install the new PAM libraries.
&lt;br&gt;&lt;br&gt;The fixed source may be obtained from the NetBSD CVS repository.
&lt;br&gt;The following instructions briefly summarize how to upgrade your PAM
&lt;br&gt;libraries by updating your source tree and rebuilding and installing
&lt;br&gt;a new version of them.
&lt;br&gt;&lt;br&gt;* NetBSD-current:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD-current dated from before 2009-06-15
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; should be upgraded to NetBSD-current dated 2009-06-16 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-current CVS branch (aka HEAD):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lib/libpam/modules/pam_unix
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install pam_unix:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P lib/libpam/modules/pam_unix
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd lib/libpam/modules/pam_unix
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;* NetBSD 5.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 5.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-05-17 should be upgraded from NetBSD 5.* sources dated
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-05-18 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-5 or netbsd-5-0 CVS branch:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lib/libpam/modules/pam_unix
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install pam_unix:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P -r &amp;lt;branch_name&amp;gt; lib/libpam/modules/pam_unix
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd lib/libpam/modules/pam_unix
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;* NetBSD 4.*:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 4.* sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-05-17 should be upgraded from NetBSD 4.* sources dated
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-05-18 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-4 or netbsd-4-0 CVS branch:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lib/libpam/modules/pam_unix
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install pam_unix:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P -r &amp;lt;branch_name&amp;gt; lib/libpam/modules/pam_unix
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd lib/libpam/modules/pam_unix
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;Thomas Getzke for discovering the vulnerability, Hubert Feyrer for
&lt;br&gt;reporting the vulnerability and testing the patches, and Tonnerre
&lt;br&gt;Lombard for providing the fix.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-22	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at 
&lt;br&gt;&amp;nbsp; ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-004.txt.asc
&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-004.txt,v 1.1 2009/06/22 19:31:01 tonnerre Exp $
&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQCVAwUBSj/8Sj5Ru2/4N2IFAQJr7AQAmNZG2k3jYrm6OMq2zZLYGv2VIff3ua77
&lt;br&gt;m/1gqntBFOh4djm/eP8AQS9Bqp7qR/f5HgDzRdJ7ib4U+geQdmV2Zco1kxMZ2KW/
&lt;br&gt;nVsjw2b+SOr4e36x33k2NNV5Odl2TSgGzXCGDbKkTv67vg46KPfP/zfJgjhA17kG
&lt;br&gt;cFf7Tt4z/Yg=
&lt;br&gt;=bZF9
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-004%3A-NetBSD-OpenPAM-passwd%281%29-changing-weakness-tp24174567p24174567.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24174538</id>
	<title>NetBSD Security Advisory 2009-003: proplib crashes on reading bad XML data</title>
	<published>2009-06-23T14:00:44Z</published>
	<updated>2009-06-23T14:00:44Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-003
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		proplib crashes on reading bad XML data
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:		affected prior to March 30, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:		not affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.1:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:		affected
&lt;br&gt;&lt;br&gt;Severity:	Denial of service
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current:		March 30, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5 branch:	March 30, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (5.0 includes the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4-0 branch:	March 31, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (4.0.2 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4 branch:	March 31, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (4.1 will include the fix)
&lt;br&gt;&lt;br&gt;Please note that NetBSD releases prior to 4.0 are no longer supported.
&lt;br&gt;It is recommended that all users upgrade to a supported release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;The proplib library can crash if a badly formatted externalized plist
&lt;br&gt;is presented for import. The crash will happen during the
&lt;br&gt;transformation of the text XML form into a binary list. This bug can
&lt;br&gt;lead to a system panic because many drivers use proplib as a
&lt;br&gt;communication channel.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;The proplib library can crash if it is presented with a non-defined
&lt;br&gt;element (e.g. &amp;lt;number&amp;gt;) in the external XML form. &amp;nbsp;During internalization
&lt;br&gt;proplib will crash by dereferencing a NULL pointer.
&lt;br&gt;&lt;br&gt;Every driver which uses proplib for user to kernel communication is
&lt;br&gt;vulnerable to this bug, allowing a system to be crashed by an ordinary
&lt;br&gt;user with access to the driver.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;For all NetBSD versions, you need to obtain fixed sources, rebuild and
&lt;br&gt;install a new kernel, and reboot the system.
&lt;br&gt;&lt;br&gt;The fixed source may be obtained from the NetBSD CVS repository.
&lt;br&gt;The following instructions briefly summarize how to upgrade your
&lt;br&gt;kernel. &amp;nbsp;In these instructions, replace:
&lt;br&gt;&lt;br&gt;&amp;nbsp; ARCH &amp;nbsp; &amp;nbsp; with your architecture (from uname -m), and
&lt;br&gt;&amp;nbsp; KERNCONF with the name of your kernel configuration file.
&lt;br&gt;&lt;br&gt;To update from CVS, re-build, and re-install the kernel:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P common/lib/libprop/prop_object.c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # ./build.sh kernel=KERNCONF
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # mv /netbsd /netbsd.old
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cp sys/arch/ARCH/compile/obj/KERNCONF/netbsd /netbsd
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # shutdown -r now
&lt;br&gt;&lt;br&gt;For more information on how to do this, see:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.NetBSD.org/guide/en/chap-kernel.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/guide/en/chap-kernel.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Recompiling and reinstalling the userlevel libprop (located in
&lt;br&gt;src/lib/libprop) may be prudent to prevent unexpected crashes of
&lt;br&gt;userland code, but should not be necessary for security purposes.
&lt;br&gt;&lt;br&gt;In order to recompile and reinstall your userlevel libprop:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src/lib/libprop
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;Adam Hamsik for the fix and initial analysis of the issue and for
&lt;br&gt;the first draft of this advisory, and to Soren Jacobsen and David
&lt;br&gt;Holland for assistance with the content of this advisory.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-22	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at
&lt;br&gt;&amp;nbsp; ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-003.txt.asc
&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-003.txt,v 1.1 2009/06/22 19:31:01 tonnerre Exp $
&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQCVAwUBSj/8RT5Ru2/4N2IFAQJdvgP/edYmzjp0DlDjo6glc6w8K9diUQQ+92SG
&lt;br&gt;5U42Kmf/hRxnHn0hZLXB7txLSWfks9DFiTVfGWyBXKFtS9h05YfWCjP1flwxvviN
&lt;br&gt;Uv8y8iDB/krAq9lR9M0x3CMlpe7Hfzpje04fXRLxUloLA427EWGCXA2noyNhPpnu
&lt;br&gt;OKn8ivX4VUs=
&lt;br&gt;=setc
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-003%3A-proplib-crashes-on-reading-bad-XML-data-tp24174538p24174538.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24174502</id>
	<title>NetBSD Security Advisory 2009-002: tcpdump multiple denial of service and arbitrary code execution issues</title>
	<published>2009-06-23T13:59:43Z</published>
	<updated>2009-06-23T13:59:43Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-002
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		tcpdump multiple denial of service and arbitrary code
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; execution issues
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:		affected before July 20, 2007
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:		not affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.*:		not affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:		affected
&lt;br&gt;&lt;br&gt;Severity:	Denial of Service, Arbitrary Code Execution
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current:		July 20, 2007
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4-0 branch:	July 21, 2008
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (4.0.2 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-4 branch:	July 21, 2008
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (4.1 will include the fix)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pkgsrc:			tcpdump-3.9.7 corrects the issue
&lt;br&gt;&lt;br&gt;Please note that NetBSD releases prior to 4.0 are no longer supported.
&lt;br&gt;It is recommended that all users upgrade to a supported release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;A number of issuses exist in the version of tcpdump(1) shipped with
&lt;br&gt;NetBSD 4.0 allowing a remote attacker to hang or crash the
&lt;br&gt;application and to execute arbitrary code via specially crafted
&lt;br&gt;packages.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;An integer overflow in the BGP dissector allows remote attackers
&lt;br&gt;to execute arbitrary code via crafted TLVs in a BGP packet.
&lt;br&gt;&lt;br&gt;An infinite loop error in the BGP dissector allows remote attackers
&lt;br&gt;to cause an application hang by sending an invalid prefix.
&lt;br&gt;&lt;br&gt;An off-by-one error in the 802.11 dissector result printing code
&lt;br&gt;allows remote attackers to crash the application.
&lt;br&gt;&lt;br&gt;An infinite loop error in the ISIS dissector allows remote attackers
&lt;br&gt;to cause an application hang using GRE packets of zero length.
&lt;br&gt;&lt;br&gt;A length verification error in the RSVP dissector allows remote
&lt;br&gt;attackers to crash the application by sending a RSVP packet of
&lt;br&gt;length 4.
&lt;br&gt;&lt;br&gt;For more details, please see CVE-2007-1218, CVE-2007-3798,
&lt;br&gt;CAN-2005-1267, CAN-2005-1278, CAN-2005-1279 and CAN-2005-1280.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;The 4.0.1 release of NetBSD resolves this issue, so a possible
&lt;br&gt;solution is to upgrade to NetBSD 4.0.1 or 5.0.
&lt;br&gt;As a temporary workaround disable tcpdump(1) from the base OS and use the
&lt;br&gt;tcpdump-3.9.7 package from pkgsrc which contains a fix.
&lt;br&gt;&lt;br&gt;The following instructions describe how to upgrade your tcpdump
&lt;br&gt;binaries by updating your source tree and rebuilding and
&lt;br&gt;installing a new version of tcpdump.
&lt;br&gt;&lt;br&gt;* NetBSD-current:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD-current dated from before 2007-07-20
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; should be upgraded to NetBSD-current dated 2007-07-21 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-current CVS branch (aka HEAD):
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/tcpdump
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install tcpdump:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P dist/tcpdump
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/tcpdump
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;* NetBSD 4.0:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The binary distribution of NetBSD 4.0 is vulnerable.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Systems running NetBSD 4.0 sources dated from before
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-07-21 should be upgraded from NetBSD 4.0 sources dated
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2008-07-22 or later.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The following directories need to be updated from the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; netbsd-4 CVS branch:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; dist/tcpdump
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To update from CVS, re-build, and re-install tcpdump:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P -r netbsd-4-0 dist/tcpdump
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd usr.sbin/tcpdump
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no cleandir dependall
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # make USETOOLS=no install
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;Moritz Jodeit, mu-b of digit-labs.org and Vade79 for finding and
&lt;br&gt;reporting the issue.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-06-22	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at 
&lt;br&gt;&amp;nbsp; ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-002.txt.asc
&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-002.txt,v 1.1 2009/06/22 19:31:01 tonnerre Exp $
&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQCVAwUBSj/8Pz5Ru2/4N2IFAQJwAgQArhKtjrbCGGk0s4bygOqxt5LsNqguTHFZ
&lt;br&gt;YTPmU51AFQnxMRyzwnOxW9zgTlIyaR6vMDjyCyNm+ewARvlGpfkiZjg6CwCesRV5
&lt;br&gt;/cAooLhV8gjAe37y/2IEmPViuXRDwa0WngjHxDr8uVeMKcWLIQ8naoI//6DZDBz/
&lt;br&gt;ft2GwdxEIi4=
&lt;br&gt;=jtOE
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-002%3A-tcpdump-multiple-denial-of-service-and-arbitrary-code-execution-issues-tp24174502p24174502.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-24174263</id>
	<title>NetBSD Security Advisory 2009-001: PF firewall remote Denial Of Service attack</title>
	<published>2009-06-23T13:50:27Z</published>
	<updated>2009-06-23T13:50:27Z</updated>
	<author>
		<name>NetBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;NetBSD Security Advisory 2009-001
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;=================================
&lt;br&gt;&lt;br&gt;Topic:		PF firewall remote Denial Of Service attack
&lt;br&gt;&lt;br&gt;Version:	NetBSD-current:		affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 5.0:		not affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0.*:		not affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 4.0:		not affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 3.1.*:		not affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 3.1:		not affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 3.0.*:		not affected
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD 3.0:		not affected
&lt;br&gt;&lt;br&gt;Severity:	Denial of service
&lt;br&gt;&lt;br&gt;Fixed:		NetBSD-current:		April 14, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; NetBSD-5 branch:	April 14, 2009
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (5.0 includes the fix)
&lt;br&gt;&lt;br&gt;Please note that NetBSD releases prior to 4.0 are no longer supported.
&lt;br&gt;It is recommended that all users upgrade to a supported release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Abstract
&lt;br&gt;========
&lt;br&gt;&lt;br&gt;PF firewalls suffer from a remote denial of service attack (system
&lt;br&gt;panic) due to mishandling of some ICMP and ICMPV6 packets.
&lt;br&gt;&lt;br&gt;Technical Details
&lt;br&gt;=================
&lt;br&gt;&lt;br&gt;When a PF firewall using nat or rdr receives a specially crafted
&lt;br&gt;packet, a null pointer dereference causes a kernel panic.
&lt;br&gt;&lt;br&gt;In pf_test_rule() ICMP logic was implied for IPv6 packets and ICMPv6 logic
&lt;br&gt;was implied for IPv4 packets. The wrong ICMP header length is used and an
&lt;br&gt;assertion fails due to the attempt to access unallocated memory.
&lt;br&gt;&lt;br&gt;See also:
&lt;br&gt;&lt;a href=&quot;http://www.securityfocus.com/archive/1/502634&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.securityfocus.com/archive/1/502634&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://www.helith.net/txt/multiple_vendor-PF_null_pointer_dereference.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.helith.net/txt/multiple_vendor-PF_null_pointer_dereference.txt&lt;/a&gt;&lt;br&gt;&lt;br&gt;Solutions and Workarounds
&lt;br&gt;=========================
&lt;br&gt;&lt;br&gt;Only kernels compiled with the following option are vulnerable to this issue:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; pseudo-device pf
&lt;br&gt;&lt;br&gt;As a temporary workaround recompile the kernel with the above option 
&lt;br&gt;commented out. &amp;nbsp;The default NetBSD GENERIC kernels do not have this
&lt;br&gt;option enabled. &amp;nbsp;In addition to this the system must be running
&lt;br&gt;with nat and/or rdr rules present in the active ruleset.
&lt;br&gt;&lt;br&gt;An additional workaround can be to add the following rules to your 
&lt;br&gt;/etc/pf.conf configuration file:
&lt;br&gt;&lt;br&gt;nat/rdr ... inet proto { tcp udp icmp } ...
&lt;br&gt;nat/rdr ... inet6 proto { tcp udp icmp6 } ...
&lt;br&gt;&lt;br&gt;For all NetBSD versions, you need to obtain fixed kernel sources,
&lt;br&gt;rebuild and install the new kernel, and reboot the system.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;The fixed source may be obtained from the NetBSD CVS repository. &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;The following instructions briefly summarize how to upgrade your &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;kernel. &amp;nbsp;In these instructions, replace:
&lt;br&gt;&lt;br&gt;&amp;nbsp; ARCH &amp;nbsp; &amp;nbsp; with your architecture (from uname -m), and &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;nbsp; KERNCONF with the name of your kernel configuration file. &amp;nbsp; &amp;nbsp;
&lt;br&gt;&lt;br&gt;To update from CVS, re-build, and re-install the kernel:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cd src
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cvs update -d -P sys/dist/pf/net/pf.c
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # ./build.sh kernel=KERNCONF
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # mv /netbsd /netbsd.old
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # cp sys/arch/ARCH/compile/obj/KERNCONF/netbsd /netbsd 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # shutdown -r now
&lt;br&gt;&lt;br&gt;For more information on how to do this, see: &amp;nbsp; &amp;nbsp;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.NetBSD.org/guide/en/chap-kernel.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/guide/en/chap-kernel.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks To
&lt;br&gt;=========
&lt;br&gt;&lt;br&gt;&amp;quot;Rembrandt&amp;quot; is credited with the discovery of this issue.
&lt;br&gt;Christos Zoulas for applying the OpenBSD fix.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Revision History
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 2009-03-15	Initial release
&lt;br&gt;&lt;br&gt;&lt;br&gt;More Information
&lt;br&gt;================
&lt;br&gt;&lt;br&gt;Advisories may be updated as new information becomes available.
&lt;br&gt;The most recent version of this advisory (PGP signed) can be found at 
&lt;br&gt;&amp;nbsp; ftp://ftp.NetBSD.org/pub/NetBSD/security/advisories/NetBSD-SA2009-001.txt.asc
&lt;br&gt;&lt;br&gt;Information about NetBSD and NetBSD security can be found at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/&lt;/a&gt;&amp;nbsp;and &lt;a href=&quot;http://www.NetBSD.org/Security/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/Security/&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Copyright 2009, The NetBSD Foundation, Inc. &amp;nbsp;All Rights Reserved.
&lt;br&gt;Redistribution permitted only in full, unmodified form.
&lt;br&gt;&lt;br&gt;$NetBSD: NetBSD-SA2009-001.txt,v 1.1 2009/06/22 19:31:01 tonnerre Exp $
&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iQCVAwUBSj/8Cj5Ru2/4N2IFAQJlDwP9Eggc2LerlYb8vqLDBxP5hP2nQSZmW4Go
&lt;br&gt;sUdsUTVif28lroTl4JA7Jk5pws65KaD9ST9hMgALk7w0g6G0xm17yJwBQxobzmpw
&lt;br&gt;mY87797lDxFGWAyTBbY00ChyrSKSnsq6hTeMjt3/45hlkClIMk0nnL6oJ9DvkzMr
&lt;br&gt;sg759/2biBo=
&lt;br&gt;=vrEJ
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-Security-Advisory-2009-001%3A-PF-firewall-remote-Denial-Of-Service-attack-tp24174263p24174263.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23814596</id>
	<title>planned network maintenance June 4th, 0100-0400 UTC</title>
	<published>2009-06-01T05:18:32Z</published>
	<updated>2009-06-01T05:18:32Z</updated>
	<author>
		<name>spz</name>
	</author>
	<content type="html">Dear all,
&lt;br&gt;&lt;br&gt;ISC has announced a maintenance window for the connectivity of:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mail.NetBSD.org
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.NetBSD.org (aka gnats.NetBSD.org, aka releng.NetBSD.org)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ftp.NetBSD.org
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; anoncvs.NetBSD.org
&lt;br&gt;&lt;br&gt;June 4th, 0100-0400 UTC. This maintenance window also affects other
&lt;br&gt;services hosted at ISC in San Francisco and Redwood City.
&lt;br&gt;&lt;br&gt;We totally disinterestedly ( ;-) ) wish ISC the best of luck and success
&lt;br&gt;with their planned work.
&lt;br&gt;&lt;br&gt;regards,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; spz
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/planned-network-maintenance-June-4th%2C-0100-0400-UTC-tp23814596p23814596.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23793868</id>
	<title>End of life for 3.x</title>
	<published>2009-05-29T23:56:02Z</published>
	<updated>2009-05-29T23:56:02Z</updated>
	<author>
		<name>snj</name>
	</author>
	<content type="html">In keeping with NetBSD's policy of supporting only the current (5.x) and
&lt;br&gt;next most recent (4.x) release branches, the release of 5.0 marks the end
&lt;br&gt;of life for the 3.x branches. &amp;nbsp;We have provided an extra month of support
&lt;br&gt;for 3.x in order to give people time to migrate their machines to a newer
&lt;br&gt;release, and this one month period will be part of our support policy in
&lt;br&gt;the future.
&lt;br&gt;&lt;br&gt;The following branches will no longer be maintained:
&lt;br&gt;netbsd-3-0
&lt;br&gt;netbsd-3-1
&lt;br&gt;netbsd-3
&lt;br&gt;&lt;br&gt;This means:
&lt;br&gt;- There will be no more pullups to the branches (even for security issues)
&lt;br&gt;- There will be no security advisories made for any of the 3.x releases
&lt;br&gt;- The existing 3.x releases on ftp.NetBSD.org will be moved into
&lt;br&gt;&amp;nbsp; /pub/NetBSD-archive/
&lt;br&gt;&lt;br&gt;Soren
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/End-of-life-for-3.x-tp23793868p23793868.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23362027</id>
	<title>Thread scheduling and related interfaces in NetBSD 5.0</title>
	<published>2009-05-03T13:45:56Z</published>
	<updated>2009-05-03T13:45:56Z</updated>
	<author>
		<name>Mindaugas Rasiukevicius</name>
	</author>
	<content type="html">Dear All,
&lt;br&gt;&lt;br&gt;A lot of new features were implemented in the NetBSD 5.0 release, and many
&lt;br&gt;improvements were made in the areas of scheduling and threading. &amp;nbsp;Please
&lt;br&gt;find the PDF document which shortly reviews new scheduling interfaces.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;quot;Thread scheduling and related interfaces in NetBSD 5.0&amp;quot;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.netbsd.org/~rmind/pub/netbsd_5_scheduling_apis.pdf&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.netbsd.org/~rmind/pub/netbsd_5_scheduling_apis.pdf&lt;/a&gt;&lt;br&gt;&lt;br&gt;Thank you.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Mindaugas
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Thread-scheduling-and-related-interfaces-in-NetBSD-5.0-tp23362027p23362027.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23306297</id>
	<title>NetBSD 5.0: an overview</title>
	<published>2009-04-29T14:51:51Z</published>
	<updated>2009-04-29T14:51:51Z</updated>
	<author>
		<name>Andrew Doran-7</name>
	</author>
	<content type="html">With the release of NetBSD 5.0, I have prepared a short presentation giving
&lt;br&gt;an overview of the new features and performance improvements that 5.0
&lt;br&gt;provides. The slides can be found at the URLs below for your perusal.
&lt;br&gt;&lt;br&gt;Many thanks,
&lt;br&gt;Andrew
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.netbsd.org/~ad/50/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.netbsd.org/~ad/50/&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(HTML format, browseable)
&lt;br&gt;&lt;a href=&quot;http://www.netbsd.org/~ad/50.pdf&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.netbsd.org/~ad/50.pdf&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (Adobe PDF, printable) &amp;nbsp; 
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-5.0%3A-an-overview-tp23306297p23306297.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23306216</id>
	<title>Announcing NetBSD 5.0</title>
	<published>2009-04-29T14:49:50Z</published>
	<updated>2009-04-29T14:49:50Z</updated>
	<author>
		<name>snj</name>
	</author>
	<content type="html">On behalf of the NetBSD developers, I am proud to announce that
&lt;br&gt;NetBSD 5.0, the thirteenth release of the NetBSD operating system,
&lt;br&gt;is now available.
&lt;br&gt;&lt;br&gt;NetBSD 5.0 features greatly improved performance and scalability on
&lt;br&gt;modern multiprocessor (SMP) and multi-core systems. &amp;nbsp;Multi-threaded
&lt;br&gt;applications can now efficiently make use of more than one CPU or core,
&lt;br&gt;and system performance is much better under I/O and network load.
&lt;br&gt;&lt;br&gt;This improved performance is the result of a rewritten threading
&lt;br&gt;subsystem based on a 1:1 threading model, new kernel synchronization
&lt;br&gt;primitives, kernel preemption, a rewritten scheduler implementation,
&lt;br&gt;real-time scheduling extensions, processor sets, and dynamic CPU sets
&lt;br&gt;for thread affinity. &amp;nbsp;Almost all core kernel subsystems, like virtual
&lt;br&gt;memory, memory allocators, file system frameworks for major file
&lt;br&gt;systems, and others were audited and overhauled to make use of highly
&lt;br&gt;concurrent algorithms.
&lt;br&gt;&lt;br&gt;In addition to scalability and performance improvements, a significant
&lt;br&gt;number of major features have been added. Some highlights are: a preview
&lt;br&gt;of metadata journaling for FFS file systems (known as WAPBL, Write
&lt;br&gt;Ahead Physical Block Logging), the 'jemalloc' memory allocator, the
&lt;br&gt;X.Org X11 distribution instead of XFree86 on a number of ports, the
&lt;br&gt;Power Management Framework, ACPI suspend/resume support on many
&lt;br&gt;laptops, write support for UDF file systems, the Automated Testing
&lt;br&gt;Framework, the Runnable Userspace Meta Program framework, Xen 3.3
&lt;br&gt;support for both i386 and amd64, POSIX message queues and
&lt;br&gt;asynchronous I/O, and many new hardware device drivers.
&lt;br&gt;&lt;br&gt;For full details, please see the release notes at:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.NetBSD.org/releases/formal-5/NetBSD-5.0.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/releases/formal-5/NetBSD-5.0.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;ISO images can be downloaded using BitTorrent, and we encourage users
&lt;br&gt;who wish to install via ISO images to take advantage of this, as the
&lt;br&gt;images are very well seeded.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.NetBSD.org/mirrors/torrents/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/mirrors/torrents/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Complete source and binaries for NetBSD 5.0 are available for download
&lt;br&gt;at many sites around the world. A list of download sites providing FTP,
&lt;br&gt;AnonCVS, and other services may be found at:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.NetBSD.org/mirrors/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/mirrors/&lt;/a&gt;&lt;br&gt;&lt;br&gt;We are very grateful to all of those who donated during the 2007 fund
&lt;br&gt;drive, which brought us many of the great advances found in 5.0. &amp;nbsp;For
&lt;br&gt;more information on how you can help NetBSD, see
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.NetBSD.org/donations/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/donations/&lt;/a&gt;&lt;br&gt;&lt;br&gt;The NetBSD Foundation would like to thank all those who have
&lt;br&gt;contributed code, hardware, documentation, funds, colocation for our
&lt;br&gt;servers, web pages and other documentation, release engineering, and
&lt;br&gt;other resources over the years. More information on the people who
&lt;br&gt;make NetBSD happen is available at:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.NetBSD.org/people/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/people/&lt;/a&gt;&lt;br&gt;&lt;br&gt;We would like to especially thank the University of California at
&lt;br&gt;Berkeley and the GNU Project for particularly large subsets of code
&lt;br&gt;that we use. We would also like to thank the Internet Systems
&lt;br&gt;Consortium Inc., the Network Security Lab at Columbia University's
&lt;br&gt;Computer Science Department, and Ludd (Luleaa Academic Computer
&lt;br&gt;Society) computer society at Luleaa University of Technology for
&lt;br&gt;current colocation services.
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Announcing-NetBSD-5.0-tp23306216p23306216.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23247585</id>
	<title>Announcing the NetBSD Project Blog</title>
	<published>2009-04-26T15:09:47Z</published>
	<updated>2009-04-26T15:09:47Z</updated>
	<author>
		<name>Mark Weinem-5</name>
	</author>
	<content type="html">It is with great pleasure that I am able to officially announce the new 
&lt;br&gt;NetBSD Project Blog:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://blog.NetBSD.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://blog.NetBSD.org&lt;/a&gt;&lt;br&gt;&lt;br&gt;The NetBSD Project Blog allows us to let you, the community, know about 
&lt;br&gt;new developments in NetBSD and pkgsrc. The blog supplements our existing 
&lt;br&gt;netbsd-announce mailing list and the &amp;quot;Recent Changes and News&amp;quot; webpage. 
&lt;br&gt;We hope it will provide you with greater insight into the future of 
&lt;br&gt;NetBSD.
&lt;br&gt;&lt;br&gt;For those that tweet - so do we - &lt;a href=&quot;http://www.twitter.com/NetBSD&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.twitter.com/NetBSD&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Mark Weinem
&lt;br&gt;on behalf of the NetBSD Marketing Team
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Announcing-the-NetBSD-Project-Blog-tp23247585p23247585.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23148757</id>
	<title>Summer of Code projects selected</title>
	<published>2009-04-20T19:44:23Z</published>
	<updated>2009-04-20T19:44:23Z</updated>
	<author>
		<name>Jan Schaumann-2</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;For the fifth consecutive year, the NetBSD Project is proud to
&lt;br&gt;participate in Google's Summer of Code program[1] as a mentoring
&lt;br&gt;organization and we're pleased to announce the list of projects[2] that
&lt;br&gt;have been accepted for this summer. &amp;nbsp;This year's selected students
&lt;br&gt;include a number of NetBSD developers, returning SoC alumni and a few
&lt;br&gt;freshmen. &amp;nbsp;We're very excited to have projects ranging from the areas of
&lt;br&gt;filesystems over install automation to userland tools and we expect the
&lt;br&gt;entire NetBSD community to benefit tremendously.
&lt;br&gt;&lt;br&gt;In the coming weeks, you will see our students engage the NetBSD
&lt;br&gt;community for support with their projects; please give them a warm
&lt;br&gt;welcome and help our developers, students and mentors lead all these
&lt;br&gt;projects to success!
&lt;br&gt;&lt;br&gt;[1] &lt;a href=&quot;http://code.google.com/soc/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://code.google.com/soc/&lt;/a&gt;&lt;br&gt;[2] &lt;a href=&quot;http://www.NetBSD.org/foundation/press/soc2009.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/foundation/press/soc2009.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFJ7TLYfFtkr68iakwRAoS/AJwJFAKjFYK1eB6Fw7dMlN+0Ei1NpQCg9vb+
&lt;br&gt;Jaowkpoc3Lig2x7+MxM7ZQc=
&lt;br&gt;=ghvZ
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Summer-of-Code-projects-selected-tp23148757p23148757.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23112345</id>
	<title>IPv6 Prefix change for the NetBSD servers at ISC</title>
	<published>2009-04-17T15:47:00Z</published>
	<updated>2009-04-17T15:47:00Z</updated>
	<author>
		<name>S.P.Zeidler</name>
	</author>
	<content type="html">Dear all,
&lt;br&gt;&lt;br&gt;just in case somebody has actual IPv6 addresses in use somewhere
&lt;br&gt;instead of DNS names:
&lt;br&gt;&lt;br&gt;The IPv6 prefix for the NetBSD servers at ISC renumbers from
&lt;br&gt;2001:4f8:4:7::/64 to 2001:4f8:3:7::/64.
&lt;br&gt;&lt;br&gt;best regards,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; spz
&lt;br&gt;-- 
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=23112345&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;spz@...&lt;/a&gt; (S.P.Zeidler)
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/IPv6-Prefix-change-for-the-NetBSD-servers-at-ISC-tp23112345p23112345.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-23085136</id>
	<title>NetBSD 5.0_RC4 binaries available for download</title>
	<published>2009-04-16T12:46:39Z</published>
	<updated>2009-04-16T12:46:39Z</updated>
	<author>
		<name>snj</name>
	</author>
	<content type="html">In the immortal words of Dr. Zoidberg, &amp;quot;Hooray!&amp;quot;
&lt;br&gt;&lt;br&gt;Today, we have two things to be happy about. &amp;nbsp;First, the fourth release
&lt;br&gt;candidate of NetBSD 5.0 is available for download. &amp;nbsp;Second, this
&lt;br&gt;announcement, like RC3's, coincides with an important birthday: that of
&lt;br&gt;Billy West.
&lt;br&gt;&lt;br&gt;Below are some highlighted changes since RC3:
&lt;br&gt;- Added the RLIMIT_AS resource, which limits the total address space
&lt;br&gt;&amp;nbsp; available to processes.
&lt;br&gt;- Improved NFS server stability
&lt;br&gt;- FFS improvements
&lt;br&gt;- A fix for a pf(4) DoS
&lt;br&gt;- re(4) now works with the RealTek 8111C, which is found on many current
&lt;br&gt;&amp;nbsp; motherboards with Intel chipsets
&lt;br&gt;&lt;br&gt;As usual, src/doc/CHANGES-5.0 has the full details.
&lt;br&gt;&lt;br&gt;Binaries of 5.0_RC4 are available for download at
&lt;br&gt;&lt;br&gt;ftp://ftp.NetBSD.org/pub/NetBSD-daily/netbsd-5-0-RC4/
&lt;br&gt;&lt;br&gt;Those of you tracking by source can either continue following the netbsd-5
&lt;br&gt;branch or use the netbsd-5-0-RC4 tag.
&lt;br&gt;&lt;br&gt;As always, we want your feedback. &amp;nbsp;This time, we are especially
&lt;br&gt;interested in hearing from people who are using NFS.
&lt;br&gt;&lt;br&gt;Soren
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-5.0_RC4-binaries-available-for-download-tp23085136p23085136.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22643162</id>
	<title>NetBSD to participate again in Google's Summer of Code</title>
	<published>2009-03-21T19:27:09Z</published>
	<updated>2009-03-21T19:27:09Z</updated>
	<author>
		<name>Jan Schaumann-2</name>
	</author>
	<content type="html">&lt;br&gt;-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;For the fifth year in a row, the NetBSD Project has been selected as a
&lt;br&gt;mentoring organization in Google's Summer of Code[1]. &amp;nbsp;As in previous
&lt;br&gt;years, this provides a great opportunity for students to get paid to
&lt;br&gt;hack on NetBSD, learn about contributing to a major open source project
&lt;br&gt;and to become part of an exciting community.
&lt;br&gt;&lt;br&gt;Students interested in applying should now start to outline their
&lt;br&gt;project proposals and initiate contact with possible mentors and the
&lt;br&gt;community at large. &amp;nbsp;A list of project suggestions is available at
&lt;br&gt;&lt;a href=&quot;http://www.NetBSD.org/contrib/soc-projects.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/contrib/soc-projects.html&lt;/a&gt;, though students may
&lt;br&gt;also wish to review our general projects page[2].
&lt;br&gt;&lt;br&gt;Our NetBSD Project Application/Proposal HowTo[3] should be a good
&lt;br&gt;resource to help students develop their best proposal and the answers to
&lt;br&gt;those questions will help us to rank all applications.
&lt;br&gt;&lt;br&gt;&lt;br&gt;[1] &lt;a href=&quot;http://code.google.com/soc/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://code.google.com/soc/&lt;/a&gt;&lt;br&gt;[2] &lt;a href=&quot;http://www.NetBSD.org/contrib/projects.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/contrib/projects.html&lt;/a&gt;&lt;br&gt;[3] &lt;a href=&quot;http://www.NetBSD.org/contrib/soc-application.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/contrib/soc-application.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFJxaGlfFtkr68iakwRAuSqAKCWu/qfV2mlXKUvYrrsxKBiLQologCfdamd
&lt;br&gt;HIXmkXL17Gjkkir0X5PfVCo=
&lt;br&gt;=qKvN
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-to-participate-again-in-Google%27s-Summer-of-Code-tp22643162p22643162.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-22640874</id>
	<title>NetBSD 5.0_RC3 binaries available for download</title>
	<published>2009-03-21T13:49:36Z</published>
	<updated>2009-03-21T13:49:36Z</updated>
	<author>
		<name>snj</name>
	</author>
	<content type="html">Today, on the 16th birthday of NetBSD, I have the pleasure of announcing
&lt;br&gt;the availability of NetBSD 5.0_RC3.
&lt;br&gt;&lt;br&gt;Below are some highlighted changes since RC2:
&lt;br&gt;- Considerable improvements to WAPBL.
&lt;br&gt;- Further X.Org refinements, including switching sgimips to X.Org.
&lt;br&gt;- Scheduler Activations support is now disabled by default in sysctl.conf.
&lt;br&gt;- ddb.onpanic is now set to 1 in the kernel by default, but 0 in
&lt;br&gt;&amp;nbsp; sysctl.conf. &amp;nbsp;This avoids trying to dump if a crash occurs during the
&lt;br&gt;&amp;nbsp; install phase.
&lt;br&gt;- puffs is now enabled by default on amd64, i386, macppc, and sparc64.
&lt;br&gt;- SSP kernels should work again.
&lt;br&gt;- A handful of assorted stability improvements.
&lt;br&gt;&lt;br&gt;As always, see src/doc/CHANGES-5.0 for full details.
&lt;br&gt;&lt;br&gt;Binaries of 5.0_RC3 are available for download at
&lt;br&gt;&lt;br&gt;ftp://ftp.NetBSD.org/pub/NetBSD-daily/netbsd-5-0-RC3/
&lt;br&gt;&lt;br&gt;Those of you tracking by source can either continue following the netbsd-5
&lt;br&gt;branch or use the netbsd-5-0-RC3 tag.
&lt;br&gt;&lt;br&gt;Thanks for all the help and feedback so far. &amp;nbsp;Please keep it up!
&lt;br&gt;&lt;br&gt;Soren
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-5.0_RC3-binaries-available-for-download-tp22640874p22640874.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21947896</id>
	<title>NetBSD 5.0_RC2 binaries available for download</title>
	<published>2009-02-10T19:43:06Z</published>
	<updated>2009-02-10T19:43:06Z</updated>
	<author>
		<name>snj</name>
	</author>
	<content type="html">On behalf of the NetBSD Release Engineering team, I am proud to announce
&lt;br&gt;that the second release candidate of NetBSD 5.0 is now available for
&lt;br&gt;download.
&lt;br&gt;&lt;br&gt;Since RC1, 103 tickets were pulled up. &amp;nbsp;Interested readers can find the
&lt;br&gt;details of these tickets in src/doc/CHANGES-5.0. &amp;nbsp;RC2 represents a great
&lt;br&gt;deal of progress over RC1, but with that amount of change, increased
&lt;br&gt;time for testing is required. &amp;nbsp;To put it bluntly, there will definitely
&lt;br&gt;be a third release candidate. &amp;nbsp;We are aware of a number of
&lt;br&gt;release-blocking issues, but it is important that we get a jump on
&lt;br&gt;testing the many changes made since RC1.
&lt;br&gt;&lt;br&gt;Binaries of RC2 can be downloaded from
&lt;br&gt;&lt;br&gt;ftp://ftp.NetBSD.org/pub/NetBSD-daily/netbsd-5-0-RC2/
&lt;br&gt;&lt;br&gt;Of course, those already tracking the netbsd-5 branch by source should
&lt;br&gt;continue to to so, and the netbsd-5-0-RC2 tag is available if you prefer
&lt;br&gt;to check out the RC2 sources specifically.
&lt;br&gt;&lt;br&gt;I'd like to thank all those who have helped so far in testing and
&lt;br&gt;providing feedback. &amp;nbsp;Please keep up the good work, it is very much
&lt;br&gt;appreciated!
&lt;br&gt;&lt;br&gt;Enjoy,
&lt;br&gt;Soren
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/NetBSD-5.0_RC2-binaries-available-for-download-tp21947896p21947896.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-21792686</id>
	<title>Preparing for Summer of Code 2009</title>
	<published>2009-02-02T08:17:34Z</published>
	<updated>2009-02-02T08:17:34Z</updated>
	<author>
		<name>Jan Schaumann-2</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;Recently, Google announced that there will be another instance of their
&lt;br&gt;popular ``Summer of Code'' program in 2009. &amp;nbsp;The NetBSD Project has
&lt;br&gt;participated in this program as a mentoring organization since its
&lt;br&gt;conception in 2005 [1], and hopes again to be fortunate enough to take
&lt;br&gt;part in this year's iteration.
&lt;br&gt;&lt;br&gt;As part of our preparation for the Summer of Code 2009, we have begun
&lt;br&gt;reviewing and updating our list of suggested projects[2] and would like to
&lt;br&gt;invite all interested students to likewise begin their research and start
&lt;br&gt;discussions with the possible mentors as well as on our public mailing
&lt;br&gt;lists.
&lt;br&gt;&lt;br&gt;Stay tuned for further updates!
&lt;br&gt;&lt;br&gt;&lt;br&gt;[1] For a detailed summary of NetBSD's participation in 2008, please see
&lt;br&gt;&lt;a href=&quot;http://www.netbsd.org/foundation/press/soc2008-summary.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.netbsd.org/foundation/press/soc2008-summary.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;[2] &lt;a href=&quot;http://www.NetBSD.org/contrib/soc-projects.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.NetBSD.org/contrib/soc-projects.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (NetBSD)
&lt;br&gt;&lt;br&gt;iD8DBQFJhxxvfFtkr68iakwRAmtSAJ9Nfpu7SObYfdeKbdxnMiujC9SMbwCgq82a
&lt;br&gt;b4GbxkLmgZWvZcWJUB1PtzY=
&lt;br&gt;=tjEc
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Preparing-for-Summer-of-Code-2009-tp21792686p21792686.html" />
</entry>

</feed>
